cbcvebase.
CVE-2011-1497
published 2021-10-19

CVE-2011-1497: A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.

Affected

4 ranges
VendorProductVersion rangeFixed in
actionpack_projectactionpack>= 3.0.0.rc < 3.0.63.0.6
debianrails
rubyonrailsrails< 3.0.63.0.6
rubyonrailsrails