CVE-2010-1330
published 2012-11-23CVE-2010-1330: The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.22%
80.8th percentile
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jruby | < jruby 1.5.0~rc1-1 (bookworm) | jruby 1.5.0~rc1-1 (bookworm) |
| jruby | jruby | <= 1.4.0 | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | — | — |
| jruby | jruby | >= 0 < 1.5.0~rc1-1 | 1.5.0~rc1-1 |
| jruby | jruby | >= 0 < 1.5.0~rc1-1 | 1.5.0~rc1-1 |
| jruby | jruby | >= 0 < 1.5.0~rc1-1 | 1.5.0~rc1-1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences
vendor_redhat·2010-04-26·CVSS 4.3
CVE-2010-1330 [MEDIUM] CWE-79 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences
jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
Debian
CVE-2010-1330: jruby - The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', ...
vendor_debian·2010·CVSS 4.3
CVE-2010-1330 [MEDIUM] CVE-2010-1330: jruby - The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', ...
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
Scope: local
bookworm: resolved (fixed in 1.5.0~rc1-1)
forky: resolved (fixed in 1.5.0~rc1-1)
sid: resolved (fixed in 1.5.0~rc1-1)
trixie: resolved (fixed in 1.5.0~rc1-1)
OSV
Cross-site Scripting in in JRuby
osv·2022-05-02
CVE-2010-1330 [MEDIUM] Cross-site Scripting in in JRuby
Cross-site Scripting in in JRuby
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
GHSA
Cross-site Scripting in in JRuby
ghsa·2022-05-02
CVE-2010-1330 [MEDIUM] CWE-79 Cross-site Scripting in in JRuby
Cross-site Scripting in in JRuby
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
OSV
CVE-2010-1330: The regular expression engine in JRuby before 1
osv·2012-11-23·CVSS 4.3
CVE-2010-1330 [MEDIUM] CVE-2010-1330: The regular expression engine in JRuby before 1
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
No detection rules found.
Bugzilla
CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences [fedora-15]
bugzilla·2011-10-31·CVSS 4.3
CVE-2010-1330 [MEDIUM] CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences [fedora-15]
CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences [fedora-15]
fedora-15 tracking bug for jcodings: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This message is a notice that Fedora 15 is now at end of life. Fedora
has stopped maintaining and issuing updates for Fedora 15. It is
Fedora's policy to close all bug reports from releases that are no
longer maintained. At this time, all open bugs with a Fedora 'version'
of '15' have been closed as WONTFIX.
(Please note: Our normal process is to give advanced warning of this
occurring, but we forgot to do that. A th
Bugzilla
CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences [fedora-14]
bugzilla·2011-10-31·CVSS 4.3
CVE-2010-1330 [MEDIUM] CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences [fedora-14]
CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences [fedora-14]
fedora-14 tracking bug for jcodings: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fedora 14 is now end of life, and this issue will not be addressed.
Bugzilla
CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences
bugzilla·2011-10-31·CVSS 4.3
CVE-2010-1330 [MEDIUM] CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences
CVE-2010-1330 jruby: XSS in the regular expression engine when processing invalid UTF-8 byte sequences
A cross-site scripting (XSS) flaw was found in the way the regular expression engine of the JRuby, Java implementation of the Ruby programming language, processed certain invalid UTF-8 byte sequences. A remote attacker could use this flaw to execute arbitrary HTML or web script via specially-crafted input provided to an JRuby application.
References:
[1] http://www.jruby.org/2010/04/26/jruby-1-4-1-xss-vulnerability.html
[2] https://bugs.gentoo.org/show_bug.cgi?id=317435
Proposed upstream solution (is to upgrage to jcodings-v1.0.3):
[3] http://repo1.maven.org/maven2/org/jruby/jcodings/jcodings/1.0.3/jcodings-1.0.3.jar
Discussion:
This issue affects the versions of the jcodings package
http://rhn.redhat.com/errata/RHSA-2011-1456.htmlhttp://secunia.com/advisories/46891http://www.jruby.org/2010/04/26/jruby-1-4-1-xss-vulnerability.htmlhttp://www.osvdb.org/77297https://bugs.gentoo.org/show_bug.cgi?id=317435https://bugzilla.redhat.com/show_bug.cgi?id=750306https://exchange.xforce.ibmcloud.com/vulnerabilities/80277http://rhn.redhat.com/errata/RHSA-2011-1456.htmlhttp://secunia.com/advisories/46891http://www.jruby.org/2010/04/26/jruby-1-4-1-xss-vulnerability.htmlhttp://www.osvdb.org/77297https://bugs.gentoo.org/show_bug.cgi?id=317435https://bugzilla.redhat.com/show_bug.cgi?id=750306https://exchange.xforce.ibmcloud.com/vulnerabilities/80277
2012-11-23
Published