CVE-2012-3465
published 2012-08-10CVE-2012-3465: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.98%
78.3th percentile
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.
Affected
102 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 0 < 2.3.16 | 2.3.16 |
| actionpack_project | actionpack | >= 3.0.0.beta < 3.0.17 | 3.0.17 |
| actionpack_project | actionpack | >= 3.1.0 < 3.1.8 | 3.1.8 |
| actionpack_project | actionpack | >= 3.2.0 < 3.2.8 | 3.2.8 |
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
actionpack Cross-site Scripting vulnerability
ghsa·2017-10-24
CVE-2012-3465 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/sanitize_helper.rb` in the `strip_tags` helper in Ruby on Rails before 2.3.16, 3.0.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.
OSV
actionpack Cross-site Scripting vulnerability
osv·2017-10-24
CVE-2012-3465 [MEDIUM] actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/sanitize_helper.rb` in the `strip_tags` helper in Ruby on Rails before 2.3.16, 3.0.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.
OSV
CVE-2012-3465: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper
osv·2012-08-10·CVSS 4.3
CVE-2012-3465 [MEDIUM] CVE-2012-3465: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.
Red Hat
rubygem-actionpack: XSS Vulnerability in strip_tags
vendor_redhat·2012-08-09·CVSS 4.3
CVE-2012-3465 [MEDIUM] CWE-79 rubygem-actionpack: XSS Vulnerability in strip_tags
rubygem-actionpack: XSS Vulnerability in strip_tags
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.
Debian
CVE-2012-3465: rails - Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/s...
vendor_debian·2012·CVSS 4.3
CVE-2012-3465 [MEDIUM] CVE-2012-3465: rails - Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/s...
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 rubygem-actionpack various flaws [fedora-all]
bugzilla·2012-08-10·CVSS 4.3
CVE-2012-3463 [MEDIUM] CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 rubygem-actionpack various flaws [fedora-all]
CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 rubygem-actionpack various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?ty
Bugzilla
CVE-2012-3465 rubygem-actionpack: XSS Vulnerability in strip_tags
bugzilla·2012-08-10·CVSS 4.3
CVE-2012-3465 [MEDIUM] CVE-2012-3465 rubygem-actionpack: XSS Vulnerability in strip_tags
CVE-2012-3465 rubygem-actionpack: XSS Vulnerability in strip_tags
The Ruby on Rails project reports:
XSS Vulnerability in strip_tags
There is a vulnerability in the strip_tags helper of Ruby on Rails
which could allow an attacker to execute arbitrary javascript. This
vulnerability has been assigned the CVE identifier CVE-2012-3465.
Versions Affected: All.
Not affected: Applications not using strip_tags
Fixed Versions: 3.2.8, 3.1.8, 3.0.17
Impact
- ------
There is an XSS vulnerability in the strip_tags helper in Ruby on
Rails, the helper doesn't correctly handle malformed html. As a
result an attacker can execute arbitrary javascript through the use of
specially crafted malformed html. All users who rely on strip_tags
for XSS protection should upgrade or use the work around immediately
Bugzilla
CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2013-0156 rubygem-actionpack various flaws [epel-5]
bugzilla·2012-08-10·CVSS 4.3
CVE-2012-3463 [MEDIUM] CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2013-0156 rubygem-actionpack various flaws [epel-5]
CVE-2012-3463 CVE-2012-3464 CVE-2012-3465 CVE-2013-0156 rubygem-actionpack various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updat
http://rhn.redhat.com/errata/RHSA-2013-0154.htmlhttp://secunia.com/advisories/50694http://weblog.rubyonrails.org/2012/8/9/ann-rails-3-2-8-has-been-released/https://groups.google.com/group/rubyonrails-security/msg/7fbb5392d4d282b5?dmode=source&output=gplainhttp://rhn.redhat.com/errata/RHSA-2013-0154.htmlhttp://secunia.com/advisories/50694http://weblog.rubyonrails.org/2012/8/9/ann-rails-3-2-8-has-been-released/https://groups.google.com/group/rubyonrails-security/msg/7fbb5392d4d282b5?dmode=source&output=gplain
2012-08-10
Published