PT-2020-5648 · Ruby On Rails+1 · Action View+1

Jesse Campos

·

Published

2020-03-19

·

Updated

2024-06-15

·

CVE-2020-5267

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions ActionView versions prior to 6.0.2.2 and 5.2.4.2
Description There is a possible cross-site scripting (XSS) vulnerability in ActionView's JavaScript literal escape helpers. Views that use the j or escape javascript methods may be susceptible to XSS attacks. The issue is related to insufficient protection measures for web page structures. Exploitation of the vulnerability may allow a remote attacker to impact data integrity.
Recommendations For versions prior to 6.0.2.2 and 5.2.4.2, update to version 6.0.2.2 or 5.2.4.2 to resolve the issue. As a temporary workaround, consider applying the provided monkey patch to the JavaScriptHelper module. Restrict the use of the j and escape javascript methods in views until the issue is resolved. For those who cannot upgrade immediately, apply the provided patches for the 5.2 and 6.0 series.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01348
CVE-2020-5267
DLA-2149-1
GHSA-65CV-R6X7-79HV
OPENSUSE-SU-2020:0627-1
OPENSUSE-SU-2020:1993-1
OPENSUSE-SU-2020:2000-1
OPENSUSE-SU-2020_0627-1
OPENSUSE-SU-2020_1993-1
OPENSUSE-SU-2020_2000-1
OPENSUSE-SU-2024:11321-1
OPENSUSE-SU-2024:11823-1
RHSA-2020:4366
SUSE-SU-2020:0954-1
SUSE-SU-2020:1178-1
SUSE-SU-2020:3036-1
SUSE-SU-2020:3147-1
SUSE-SU-2020:3160-1
SUSE-SU-2020_1178-1

Affected Products

Action View
Suse