CVE-2013-1857
published 2013-03-19CVE-2013-1857: The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.87%
77.1th percentile
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.
Affected
122 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 0 < 2.3.18 | 2.3.18 |
| actionpack_project | actionpack | >= 3.0.0 < 3.1.12 | 3.1.12 |
| actionpack_project | actionpack | >= 3.2.0 < 3.2.13 | 3.2.13 |
| debian | rails | < rails 2.3.14.1 (bookworm) | rails 2.3.14.1 (bookworm) |
| redhat | enterprise_linux | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
actionpack Cross-site Scripting vulnerability
ghsa·2017-10-24
CVE-2013-1857 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
The sanitize helper in `lib/action_controller/vendor/html-scanner/html/sanitizer.rb` in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded `:` (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a `:` sequence.
OSV
actionpack Cross-site Scripting vulnerability
osv·2017-10-24
CVE-2013-1857 [MEDIUM] actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
The sanitize helper in `lib/action_controller/vendor/html-scanner/html/sanitizer.rb` in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded `:` (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a `:` sequence.
OSV
CVE-2013-1857: The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer
osv·2013-03-19·CVSS 4.3
CVE-2013-1857 [MEDIUM] CVE-2013-1857: The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.
Red Hat
rubygem-actionpack: sanitize_protocol: XSS Vulnerability in the helper of Ruby on Rails
vendor_redhat·2013-03-18·CVSS 4.3
CVE-2013-1857 [MEDIUM] CWE-79 rubygem-actionpack: sanitize_protocol: XSS Vulnerability in the helper of Ruby on Rails
rubygem-actionpack: sanitize_protocol: XSS Vulnerability in the helper of Ruby on Rails
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.
A cross-site scripting (XSS) flaw was found in Action Pack. A remote attacker could use this flaw to conduct XSS attacks against users of an application using Action Pack.
Package: ruby193-rubygem-actionpack (Red Hat Satellite 6) - Affected
Debian
CVE-2013-1857: rails - The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer....
vendor_debian·2013·CVSS 4.3
CVE-2013-1857 [MEDIUM] CVE-2013-1857: rails - The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer....
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.
Scope: local
bookworm: resolved (fixed in 2.3.14.1)
bullseye: resolved (fixed in 2.3.14.1)
forky: resolved (fixed in 2.3.14.1)
sid: resolved (fixed in 2.3.14.1)
trixie: resolved (fixed in 2.3.14.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [epel-5]
bugzilla·2013-03-21·CVSS 4.3
CVE-2013-1855 [MEDIUM] CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [epel-5]
CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for rubyge
Bugzilla
CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [fedora-all]
bugzilla·2013-03-21·CVSS 4.3
CVE-2013-1855 [MEDIUM] CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [fedora-all]
CVE-2013-1855 CVE-2013-1857 rubygem-actionpack various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects
Bugzilla
CVE-2013-1857 rubygem-actionpack: sanitize_protocol: XSS Vulnerability in the helper of Ruby on Rails
bugzilla·2013-03-14·CVSS 4.3
CVE-2013-1857 [MEDIUM] CVE-2013-1857 rubygem-actionpack: sanitize_protocol: XSS Vulnerability in the helper of Ruby on Rails
CVE-2013-1857 rubygem-actionpack: sanitize_protocol: XSS Vulnerability in the helper of Ruby on Rails
XSS Vulnerability in the `sanitize` helper of Ruby on Rails
There is an XSS vulnerability in the sanitize helper in Ruby on Rails. This vulnerability has been assigned the CVE identifier CVE-2013-1857.
Versions Affected: All.
Not affected: None.
Fixed Versions: 3.2.13, 3.1.12
Impact
The sanitize helper in Ruby on Rails is designed to filter HTML and remove all tags and attributes which could be malicious. The code which ensured that URLs only contain supported protocols contained several bugs which could allow an attacker to embed a tag containing a URL which executes arbitrary javascript code.
All users running an affected release should either upgrade or use one of the work arounds
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00072.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00073.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0698.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/https://groups.google.com/group/rubyonrails-security/msg/78b9817a5943f6d6?dmode=source&output=gplainhttp://lists.apple.com/archives/security-announce/2013/Jun/msg00000.htmlhttp://lists.apple.com/archives/security-announce/2013/Oct/msg00006.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00072.htmlhttp://lists.opensuse.org/opensuse-updates/2013-04/msg00073.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00013.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0698.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://support.apple.com/kb/HT5784http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/https://groups.google.com/group/rubyonrails-security/msg/78b9817a5943f6d6?dmode=source&output=gplain
2013-03-19
Published