CVE-2011-2197
published 2011-06-30CVE-2011-2197: The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.96%
78.4th percentile
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 2.0.0 < 2.3.12 | 2.3.12 |
| actionpack_project | actionpack | >= 3.0.0 < 3.0.8 | 3.0.8 |
| debian | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
rails Cross-site Scripting vulnerability
osv·2017-10-24
CVE-2011-2197 [MEDIUM] rails Cross-site Scripting vulnerability
rails Cross-site Scripting vulnerability
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
GHSA
rails Cross-site Scripting vulnerability
ghsa·2017-10-24
CVE-2011-2197 [MEDIUM] CWE-79 rails Cross-site Scripting vulnerability
rails Cross-site Scripting vulnerability
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
Debian
CVE-2011-2197: rails - The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2....
vendor_debian·2011·CVSS 4.3
CVE-2011-2197 [MEDIUM] CVE-2011-2197: rails - The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2....
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2197 rubygem-activesupport: XSS due improper management of safe buffers
bugzilla·2011-06-16·CVSS 4.3
CVE-2011-2197 [MEDIUM] CVE-2011-2197 rubygem-activesupport: XSS due improper management of safe buffers
CVE-2011-2197 rubygem-activesupport: XSS due improper management of safe buffers
An cross-site scripting (XSS) flaw was found in the way Ruby on Rails
performed management of safe buffers (certain methods could append
unsafe strings to buffers, already containing strings marked as safe
without marking the resulting buffer as unsafe). A remote attack could
use this flaw to conduct XSS attacks by tricking a local user into
visiting a specially-crafted web page.
References:
[1] http://weblog.rubyonrails.org/2011/6/8/potential-xss-vulnerability-in-ruby-on-rails-applications
(upstream advisory)
[2] http://www.openwall.com/lists/oss-security/2011/06/09/2
(CVE request)
[3] http://www.openwall.com/lists/oss-security/2011/06/13/9
(CVE assignment)
Upstream patches:
[4] https://gist.github.com/89d
Bugzilla
CVE-2011-2197 rubygem-activesupport: XSS due improper management of safe buffers [fedora-15]
bugzilla·2011-06-16·CVSS 4.3
CVE-2011-2197 [MEDIUM] CVE-2011-2197 rubygem-activesupport: XSS due improper management of safe buffers [fedora-15]
CVE-2011-2197 rubygem-activesupport: XSS due improper management of safe buffers [fedora-15]
fedora-15 tracking bug for rubygem-activesupport: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
rubygem-activesupport-3.0.5-3.fc15 has been submitted as an update for Fedora 15.
https://admin.fedoraproject.org/updates/rubygem-activesupport-3.0.5-3.fc15
---
Package rubygem-activesupport-3.0.5-3.fc15:
* should fix your issue,
* was pushed to the Fedora 15 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing rubygem-activesupport-3
http://groups.google.com/group/rubyonrails-security/msg/663b600d4471e0d4?dmode=source&output=gplainhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062514.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/062090.htmlhttp://openwall.com/lists/oss-security/2011/06/09/2http://openwall.com/lists/oss-security/2011/06/13/9http://secunia.com/advisories/44789http://weblog.rubyonrails.org/2011/6/8/potential-xss-vulnerability-in-ruby-on-rails-applicationshttp://groups.google.com/group/rubyonrails-security/msg/663b600d4471e0d4?dmode=source&output=gplainhttp://lists.fedoraproject.org/pipermail/package-announce/2011-July/062514.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-June/062090.htmlhttp://openwall.com/lists/oss-security/2011/06/09/2http://openwall.com/lists/oss-security/2011/06/13/9http://secunia.com/advisories/44789http://weblog.rubyonrails.org/2011/6/8/potential-xss-vulnerability-in-ruby-on-rails-applications
2011-06-30
Published