CVE-2013-1855
published 2013-03-19CVE-2013-1855: The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.64%
83.9th percentile
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
Affected
122 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 0 < 2.3.18 | 2.3.18 |
| actionpack_project | actionpack | >= 3.0.0 < 3.1.12 | 3.1.12 |
| actionpack_project | actionpack | >= 3.2.0 < 3.2.13 | 3.2.13 |
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| redhat | enterprise_linux | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: css_sanitization: XSS vulnerability in sanitize_css
vendor_redhat·2013-03-18·CVSS 4.3
CVE-2013-1855 [MEDIUM] CWE-79 rubygem-actionpack: css_sanitization: XSS vulnerability in sanitize_css
rubygem-actionpack: css_sanitization: XSS vulnerability in sanitize_css
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
A cross-site scripting (XSS) flaw was found in Action Pack. A remote attacker could use this flaw to conduct XSS attacks against users of an application using Action Pack.
Package: ruby193-rubygem-actionpack (Red Hat Satellite 6) - Affected
Debian
CVE-2013-1855: rails - The sanitize_css method in lib/action_controller/vendor/html-scanner/html/saniti...
vendor_debian·2013·CVSS 4.3
CVE-2013-1855 [MEDIUM] CVE-2013-1855: rails - The sanitize_css method in lib/action_controller/vendor/html-scanner/html/saniti...
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
GHSA
actionpack Cross-site Scripting vulnerability
ghsa·2017-10-24
CVE-2013-1855 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
The `sanitize_css` method in `lib/action_controller/vendor/html-scanner/html/sanitizer.rb` in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle `\n` (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
OSV
actionpack Cross-site Scripting vulnerability
osv·2017-10-24
CVE-2013-1855 [MEDIUM] actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
The `sanitize_css` method in `lib/action_controller/vendor/html-scanner/html/sanitizer.rb` in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle `\n` (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
OSV
CVE-2013-1855: The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer
osv·2013-03-19·CVSS 4.3
CVE-2013-1855 [MEDIUM] CVE-2013-1855: The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [epel-5]
bugzilla·2013-03-21·CVSS 4.3
CVE-2013-1855 [MEDIUM] CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [epel-5]
CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for rubyge
Bugzilla
CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [fedora-all]
bugzilla·2013-03-21·CVSS 4.3
CVE-2013-1855 [MEDIUM] CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [fedora-all]
CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-1855 rubygem-actionpack: css_sanitization: XSS vulnerability in sanitize_css
bugzilla·2013-03-14·CVSS 4.3
CVE-2013-1855 [MEDIUM] CVE-2013-1855 rubygem-actionpack: css_sanitization: XSS vulnerability in sanitize_css
CVE-2013-1855 rubygem-actionpack: css_sanitization: XSS vulnerability in sanitize_css
XSS vulnerability in sanitize_css in Action Pack
There is an XSS vulnerability in the `sanitize_css` method in Action Pack. This vulnerability has been assigned the CVE identifier CVE-2013-1855.
Versions Affected: All.
Not affected: None.
Fixed Versions: 3.2.13, 3.1.12
Impact
Carefully crafted text can bypass the sanitization provided in the `sanitize_css` method in Action Pack. Impacted code will look like this:
sanitize_css(some_user_input)
All users running an affected release should either upgrade or use one of the work arounds immediately.
Releases
The 3.2.13 and 3.1.12 releases are available at the normal locations.
Workarounds
To work around this issue, you can apply the following monkey pa
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00072.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00073.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0698.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/https://groups.google.com/group/rubyonrails-security/msg/8ed835a97cdd1afd?dmode=source&output=gplainhttp://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00072.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00073.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0698.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/https://groups.google.com/group/rubyonrails-security/msg/8ed835a97cdd1afd?dmode=source&output=gplain
2013-03-19
Published