CVE-2011-2197Cross-site Scripting in Rails

Severity
4.3MEDIUMNVD
EPSS
0.4%
top 36.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30
Latest updateOct 24

Description

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDrubyonrails/rails26 versions+25
RubyGemsactionpack_project/actionpack2.0.02.3.12+1

Patches

🔴Vulnerability Details

3
OSV
rails Cross-site Scripting vulnerability2017-10-24
GHSA
rails Cross-site Scripting vulnerability2017-10-24
CVEList
CVE-2011-2197: The cross-site scripting (XSS) prevention feature in Ruby on Rails 22011-06-30

📋Vendor Advisories

1
Debian
CVE-2011-2197: rails - The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2....2011

💬Community

2
Bugzilla
CVE-2011-2197 rubygem-activesupport: XSS due improper management of safe buffers2011-06-16
Bugzilla
CVE-2011-2197 rubygem-activesupport: XSS due improper management of safe buffers [fedora-15]2011-06-16
CVE-2011-2197 — Cross-site Scripting in Rails | cvebase