PT-2015-6105 · Ruby · Ruby On Rails

Francois Chagnon

·

Published

2015-07-26

·

Updated

2024-06-15

·

CVE-2015-3226

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 3.x through 4.1.10 Ruby on Rails versions 4.2.x through 4.2.1
Description A cross-site scripting (XSS) issue in the json/encoding.rb file of Active Support in Ruby on Rails allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding. This enables attackers to execute malicious code on the victim's browser.
Recommendations For Ruby on Rails versions 3.x through 4.1.10, update to version 4.1.11 or later. For Ruby on Rails versions 4.2.x through 4.2.1, update to version 4.2.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3226
DSA-3464-1
GHSA-VXVP-4XWC-JPP6
OPENSUSE-SU-2024:10574-1
SUSE-SU-2016:0082-1

Affected Products

Ruby On Rails