CVE-2012-1099
published 2012-03-13CVE-2012-1099: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.48%
82.7th percentile
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 3.0.0 < 3.0.12 | 3.0.12 |
| actionpack_project | actionpack | >= 3.1.0 < 3.1.4 | 3.1.4 |
| actionpack_project | actionpack | >= 3.2.0 < 3.2.2 | 3.2.2 |
| debian | rails | < rails 2.3.14 (bookworm) | rails 2.3.14 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Cross-site Scripting in actionpack
ghsa·2017-10-24
CVE-2012-1099 [MEDIUM] CWE-79 Cross-site Scripting in actionpack
Cross-site Scripting in actionpack
Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/form_options_helper.rb` in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements.
OSV
Cross-site Scripting in actionpack
osv·2017-10-24
CVE-2012-1099 [MEDIUM] Cross-site Scripting in actionpack
Cross-site Scripting in actionpack
Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/form_options_helper.rb` in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements.
OSV
CVE-2012-1099: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper
osv·2012-03-13·CVSS 4.3
CVE-2012-1099 [MEDIUM] CVE-2012-1099: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements.
Red Hat
rubygem-actionpack: XSS in the 'select' helper
vendor_redhat·2012-03-01·CVSS 4.3
CVE-2012-1099 [MEDIUM] CWE-79 rubygem-actionpack: XSS in the 'select' helper
rubygem-actionpack: XSS in the 'select' helper
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements.
Package: rubygem-actionpack (Red Hat Subscription Asset Manager) - Affected
Debian
CVE-2012-1099: rails - Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/f...
vendor_debian·2012·CVSS 4.3
CVE-2012-1099 [MEDIUM] CVE-2012-1099: rails - Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/f...
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/form_options_helper.rb in the select helper in Ruby on Rails 3.0.x before 3.0.12, 3.1.x before 3.1.4, and 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via vectors involving certain generation of OPTION elements within SELECT elements.
Scope: local
bookworm: resolved (fixed in 2.3.14)
bullseye: resolved (fixed in 2.3.14)
forky: resolved (fixed in 2.3.14)
sid: resolved (fixed in 2.3.14)
trixie: resolved (fixed in 2.3.14)
No detection rules found.
No public exploits indexed.
Bugzilla
rubygem-actionpack various flaws [fedora-all]
bugzilla·2012-03-02·CVSS 4.3
[MEDIUM] rubygem-actionpack various flaws [fedora-all]
rubygem-actionpack various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=799275
Please note: thi
Bugzilla
CVE-2012-1099 rubygem-actionpack: XSS in the 'select' helper
bugzilla·2012-03-02·CVSS 4.3
CVE-2012-1099 [MEDIUM] CVE-2012-1099 rubygem-actionpack: XSS in the 'select' helper
CVE-2012-1099 rubygem-actionpack: XSS in the 'select' helper
A cross-site scripting (XSS) flaw was found in the way 'select' helper method of the Ruby on Rails performed HTML escaping of 'select' HTML tag options, when the tags were created manually. In this case, the select tag values might end up unescaped. A remote-attacker could provide a specially-crafted input to Ruby on Rails application, using select tags this way, which potentially resulted into arbitrary HTML or webscript execution.
References:
[1] http://weblog.rubyonrails.org/2012/3/1/ann-rails-3-0-12-has-been-released
[2] http://groups.google.com/group/rubyonrails-security/browse_thread/thread/9da0c515a6c4664
[3] https://bugs.gentoo.org/show_bug.cgi?id=406547
Proposed upstream patches:
[4] http://groups.google.com/group/rub
http://groups.google.com/group/rubyonrails-security/msg/6fca4f5c47705488?dmode=source&output=gplainhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075675.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075740.htmlhttp://weblog.rubyonrails.org/2012/3/1/ann-rails-3-0-12-has-been-releasedhttp://www.debian.org/security/2012/dsa-2466http://www.openwall.com/lists/oss-security/2012/03/02/6http://www.openwall.com/lists/oss-security/2012/03/03/1https://bugzilla.redhat.com/show_bug.cgi?id=799276http://groups.google.com/group/rubyonrails-security/msg/6fca4f5c47705488?dmode=source&output=gplainhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075675.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-March/075740.htmlhttp://weblog.rubyonrails.org/2012/3/1/ann-rails-3-0-12-has-been-releasedhttp://www.debian.org/security/2012/dsa-2466http://www.openwall.com/lists/oss-security/2012/03/02/6http://www.openwall.com/lists/oss-security/2012/03/03/1https://bugzilla.redhat.com/show_bug.cgi?id=799276
2012-03-13
Published