CVE-2009-4214
published 2009-12-07CVE-2009-4214: Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
3.02%
86.1th percentile
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2.2.3-2 (bookworm) | rails 2.2.3-2 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Moderate severity vulnerability that affects rails
ghsa·2017-10-24
CVE-2009-4214 [MEDIUM] CWE-79 Moderate severity vulnerability that affects rails
Moderate severity vulnerability that affects rails
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
OSV
Moderate severity vulnerability that affects rails
osv·2017-10-24
CVE-2009-4214 [MEDIUM] Moderate severity vulnerability that affects rails
Moderate severity vulnerability that affects rails
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
OSV
CVE-2009-4214: Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2
osv·2009-12-07·CVSS 4.3
CVE-2009-4214 [MEDIUM] CVE-2009-4214: Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
Red Hat
rubygem-actionpack: XSS weakness in strip_tags
vendor_redhat·2009-11-27·CVSS 4.3
CVE-2009-4214 [MEDIUM] CWE-79 rubygem-actionpack: XSS weakness in strip_tags
rubygem-actionpack: XSS weakness in strip_tags
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
Debian
CVE-2009-4214: rails - Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on R...
vendor_debian·2009·CVSS 4.3
CVE-2009-4214 [MEDIUM] CVE-2009-4214: rails - Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on R...
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
Scope: local
bookworm: resolved (fixed in 2.2.3-2)
bullseye: resolved (fixed in 2.2.3-2)
forky: resolved (fixed in 2.2.3-2)
sid: resolved (fixed in 2.2.3-2)
trixie: resolved (fixed in 2.2.3-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://github.com/rails/rails/commit/bfe032858077bb2946abe25e95e485ba6da86bd5http://groups.google.com/group/rubyonrails-security/browse_thread/thread/4d4f71f2aef4c0ab?pli=1http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://secunia.com/advisories/37446http://secunia.com/advisories/38915http://support.apple.com/kb/HT4077http://weblog.rubyonrails.org/2009/11/30/ruby-on-rails-2-3-5-releasedhttp://www.debian.org/security/2011/dsa-2260http://www.debian.org/security/2011/dsa-2301http://www.openwall.com/lists/oss-security/2009/11/27/2http://www.openwall.com/lists/oss-security/2009/12/08/3http://www.securityfocus.com/bid/37142http://www.securitytracker.com/id?1023245http://www.vupen.com/english/advisories/2009/3352http://github.com/rails/rails/commit/bfe032858077bb2946abe25e95e485ba6da86bd5http://groups.google.com/group/rubyonrails-security/browse_thread/thread/4d4f71f2aef4c0ab?pli=1http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-03/msg00004.htmlhttp://secunia.com/advisories/37446http://secunia.com/advisories/38915http://support.apple.com/kb/HT4077http://weblog.rubyonrails.org/2009/11/30/ruby-on-rails-2-3-5-releasedhttp://www.debian.org/security/2011/dsa-2260http://www.debian.org/security/2011/dsa-2301http://www.openwall.com/lists/oss-security/2009/11/27/2http://www.openwall.com/lists/oss-security/2009/12/08/3http://www.securityfocus.com/bid/37142http://www.securitytracker.com/id?1023245http://www.vupen.com/english/advisories/2009/3352
2009-12-07
Published