CVE-2013-4491
published 2013-12-07CVE-2013-4491: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.23%
81.0th percentile
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 3.0.0 < 3.2.16 | 3.2.16 |
| actionpack_project | actionpack | >= 4.0.0 < 4.0.2 | 4.0.2 |
| debian | rails | — | — |
| rubyonrails | rails | <= 4.0.1 | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
actionpack vulnerable to Cross-site Scripting
ghsa·2017-10-24
CVE-2013-4491 [MEDIUM] CWE-79 actionpack vulnerable to Cross-site Scripting
actionpack vulnerable to Cross-site Scripting
Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/translation_helper.rb` in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
OSV
actionpack vulnerable to Cross-site Scripting
osv·2017-10-24
CVE-2013-4491 [MEDIUM] actionpack vulnerable to Cross-site Scripting
actionpack vulnerable to Cross-site Scripting
Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/translation_helper.rb` in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
OSV
CVE-2013-4491: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper
osv·2013-12-07·CVSS 4.3
CVE-2013-4491 [MEDIUM] CVE-2013-4491: Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Red Hat
rubygem-actionpack: i18n missing translation XSS
vendor_redhat·2013-12-03·CVSS 4.3
CVE-2013-4491 [MEDIUM] CWE-79 rubygem-actionpack: i18n missing translation XSS
rubygem-actionpack: i18n missing translation XSS
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
It was discovered that the internationalization component of Ruby on Rails could, under certain circumstances, return a fallback HTML string that contained user input. A remote attacker could possibly use this flaw to perform a reflective cross-site scripting (XSS) attack by providing a specially crafted input to an application using the aforementioned component.
Package: ruby193-rubygem-actionpack (Clo
Debian
CVE-2013-4491: rails - Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/t...
vendor_debian·2013·CVSS 4.3
CVE-2013-4491 [MEDIUM] CVE-2013-4491: rails - Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/t...
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1794.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0008.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://secunia.com/advisories/57836http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2014/dsa-2888http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/http://www.securityfocus.com/bid/64076https://groups.google.com/forum/message/raw?msg=ruby-security-ann/pLrh6DUw998/bLFEyIO4k_EJhttps://puppet.com/security/cve/cve-2013-4491http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1794.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0008.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://secunia.com/advisories/57836http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2014/dsa-2888http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/http://www.securityfocus.com/bid/64076https://groups.google.com/forum/message/raw?msg=ruby-security-ann/pLrh6DUw998/bLFEyIO4k_EJhttps://puppet.com/security/cve/cve-2013-4491
2013-12-07
Published