CVE-2012-3464
published 2012-08-10CVE-2012-3464: Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.57%
83.5th percentile
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.
Affected
98 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: potential XSS vulnerability
vendor_redhat·2012-08-09·CVSS 4.3
CVE-2012-3464 [MEDIUM] CWE-79 rubygem-actionpack: potential XSS vulnerability
rubygem-actionpack: potential XSS vulnerability
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.
Debian
CVE-2012-3464: rails - Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/cor...
vendor_debian·2012·CVSS 4.3
CVE-2012-3464 [MEDIUM] CVE-2012-3464: rails - Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/cor...
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
GHSA
activesupport Cross-site Scripting vulnerability
ghsa·2017-10-24
CVE-2012-3464 [MEDIUM] CWE-79 activesupport Cross-site Scripting vulnerability
activesupport Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in `activesupport/lib/active_support/core_ext/string/output_safety.rb` in Ruby on Rails before 2.3.16, 3.0.x before , 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.
OSV
activesupport Cross-site Scripting vulnerability
osv·2017-10-24
CVE-2012-3464 [MEDIUM] activesupport Cross-site Scripting vulnerability
activesupport Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in `activesupport/lib/active_support/core_ext/string/output_safety.rb` in Ruby on Rails before 2.3.16, 3.0.x before , 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.
OSV
CVE-2012-3464: Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety
osv·2012-08-10·CVSS 4.3
CVE-2012-3464 [MEDIUM] CVE-2012-3464: Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety
Cross-site scripting (XSS) vulnerability in activesupport/lib/active_support/core_ext/string/output_safety.rb in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 might allow remote attackers to inject arbitrary web script or HTML via vectors involving a ' (quote) character.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 rubygem-actionpack various flaws [fedora-all]
bugzilla·2012-08-10·CVSS 4.3
CVE-2012-3463 [MEDIUM] CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 rubygem-actionpack various flaws [fedora-all]
CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 rubygem-actionpack various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?ty
Bugzilla
CVE-2012-3464 rubygem-actionpack: potential XSS vulnerability
bugzilla·2012-08-10·CVSS 4.3
CVE-2012-3464 [MEDIUM] CVE-2012-3464 rubygem-actionpack: potential XSS vulnerability
CVE-2012-3464 rubygem-actionpack: potential XSS vulnerability
The Ruby on Rails project reports:
There is a vulnerability in the HTML escaping code in Ruby on Rails.
This vulnerability has been assigned the CVE identifier CVE-2012-3464.
Versions Affected: All.
Not affected: None
Fixed Versions: 3.2.8, 3.1.8, 3.0.17
Impact
- ------
The HTML escaping code in Ruby on Rails does not escape all
potentially dangerous characters. In particular the code does not
escape the single quote character. The helpers used in Rails itself
never use single quotes, so most applications are unlikely to be
vulnerable, however all users running an affected release should still
upgrade.
Releases
- --------
The 3.2.8 and 3.1.8 releases are available at the normal locations.
Workarounds
- -----------
For use
Bugzilla
CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2013-0156 rubygem-actionpack various flaws [epel-5]
bugzilla·2012-08-10·CVSS 4.3
CVE-2012-3463 [MEDIUM] CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2013-0156 rubygem-actionpack various flaws [epel-5]
CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2013-0156 rubygem-actionpack various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updat
Bugzilla
CVE-2011-3464 libpng: One-byte stack buffer overrun in png_formatted_warning
bugzilla·2012-07-25·CVSS 7.5
CVE-2011-3464 [HIGH] CVE-2011-3464 libpng: One-byte stack buffer overrun in png_formatted_warning
CVE-2011-3464 libpng: One-byte stack buffer overrun in png_formatted_warning
The libpng project announced that libpng 1.5.4 through 1.5.7 contain a
one-byte (stack) buffer-overrun bug in png_formatted_warning(), which could
lead to crashes (denial of service) or, conceivably, execution of hostile
code. This vulnerability has been assigned ID CVE-2011-3464 and is fixed in
version 1.5.8, released 1 February 2012.
References:
http://www.libpng.org/pub/png/libpng.html
Discussion:
Created mingw-libpng tracking bugs for this issue
Affects: fedora-17 [bug 843190]
---
Statement:
Not vulnerable. This issue did not affect the versions of libtiff as shipped with Red Hat Enterprise Linux 4, 5, and 6.
http://rhn.redhat.com/errata/RHSA-2013-0154.htmlhttp://secunia.com/advisories/50694http://weblog.rubyonrails.org/2012/8/9/ann-rails-3-2-8-has-been-released/https://groups.google.com/group/rubyonrails-security/msg/8f1bbe1cef8c6caf?dmode=source&output=gplainhttp://rhn.redhat.com/errata/RHSA-2013-0154.htmlhttp://secunia.com/advisories/50694http://weblog.rubyonrails.org/2012/8/9/ann-rails-3-2-8-has-been-released/https://groups.google.com/group/rubyonrails-security/msg/8f1bbe1cef8c6caf?dmode=source&output=gplain
2012-08-10
Published