CVE-2009-4214Cross-site Scripting in Rails

Severity
4.3MEDIUMNVD
EPSS
1.6%
top 18.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 7
Latest updateOct 24

Description

Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

RubyGemsrubyonrails/rails2.3.02.3.5+1
Debianrubyonrails/rails< 2.2.3-2+3
NVDrubyonrails/rails42 versions+41

Patches

🔴Vulnerability Details

4
GHSA
Moderate severity vulnerability that affects rails2017-10-24
OSV
Moderate severity vulnerability that affects rails2017-10-24
CVEList
CVE-2009-4214: Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 22009-12-07
OSV
CVE-2009-4214: Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 22009-12-07

📋Vendor Advisories

2
Red Hat
rubygem-actionpack: XSS weakness in strip_tags2009-11-27
Debian
CVE-2009-4214: rails - Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on R...2009
CVE-2009-4214 — Cross-site Scripting in Rails | cvebase