CVE-2013-4492
published 2013-12-07CVE-2013-4492: Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.23%
81.0th percentile
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-i18n | < ruby-i18n 0.6.9-1 (bookworm) | ruby-i18n 0.6.9-1 (bookworm) |
| i18n_project | i18n | <= 0.6.5 | — |
| i18n_project | i18n | >= 0 < 0.6.6 | 0.6.6 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
i18n gem Cross-site Scripting vulnerability
ghsa·2017-10-24
CVE-2013-4492 [MEDIUM] CWE-79 i18n gem Cross-site Scripting vulnerability
i18n gem Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
OSV
i18n gem Cross-site Scripting vulnerability
osv·2017-10-24
CVE-2013-4492 [MEDIUM] i18n gem Cross-site Scripting vulnerability
i18n gem Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
OSV
CVE-2013-4492: Cross-site scripting (XSS) vulnerability in exceptions
osv·2013-12-07·CVSS 4.3
CVE-2013-4492 [MEDIUM] CVE-2013-4492: Cross-site scripting (XSS) vulnerability in exceptions
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Red Hat
rubygem-i18n: cross-site scripting flaw in exception handling
vendor_redhat·2013-12-04·CVSS 4.3
CVE-2013-4492 [MEDIUM] CWE-79 rubygem-i18n: cross-site scripting flaw in exception handling
rubygem-i18n: cross-site scripting flaw in exception handling
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Package: ruby193-rubygem-i18n (OpenShift Enterprise 1) - Will not fix
Package: ruby193-rubygem-i18n (Red Hat OpenShift Enterprise 2) - Will not fix
Package: ruby193-rubygem-i18n (Red Hat OpenStack Platform 3) - Will not fix
Package: ruby193-rubygem-i18n (Red Hat OpenStack Platform 4) - Will not fix
Package: ror40-rubygem-i18n (Red Hat Software Collections) - Will not fix
Package: ruby193-rubygem-i18n (Red Hat Software Collections) - Will not fix
Package: ruby193-rubygem-i18n (Red Hat Subscription Asset Manager) -
Debian
CVE-2013-4492: ruby-i18n - Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before...
vendor_debian·2013·CVSS 4.3
CVE-2013-4492 [MEDIUM] CVE-2013-4492: ruby-i18n - Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before...
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Scope: local
bookworm: resolved (fixed in 0.6.9-1)
bullseye: resolved (fixed in 0.6.9-1)
forky: resolved (fixed in 0.6.9-1)
sid: resolved (fixed in 0.6.9-1)
trixie: resolved (fixed in 0.6.9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4492 rubygem-i18n: cross-site scripting flaw in exception handling
bugzilla·2013-12-09·CVSS 4.3
CVE-2013-4492 [MEDIUM] CVE-2013-4492 rubygem-i18n: cross-site scripting flaw in exception handling
CVE-2013-4492 rubygem-i18n: cross-site scripting flaw in exception handling
A cross-site scripting flaw was found in the Ruby i18n gem. A remote attacker could use this flaw to perform cross-site scripting attacks against other users.
References:
https://github.com/svenfuchs/i18n/commit/92b57b1e4f84adcdcc3a375278f299274be62445
https://bugzilla.novell.com/show_bug.cgi?id=854166
Discussion:
Created rubygem-i18n tracking bugs for this issue:
Affects: fedora-all [bug 1039441]
---
rubygem-i18n-0.6.0-2.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
---
rubygem-i18n-0.6.1-4.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
---
rub
Bugzilla
CVE-2013-4492 rubygem-i18n: cross-site scripting flaw in exception handling [fedora-all]
bugzilla·2013-12-09·CVSS 4.3
CVE-2013-4492 [MEDIUM] CVE-2013-4492 rubygem-i18n: cross-site scripting flaw in exception handling [fedora-all]
CVE-2013-4492 rubygem-i18n: cross-site scripting flaw in exception handling [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-4491 rubygem-actionpack: i18n missing translation XSS
bugzilla·2013-12-02·CVSS 4.3
CVE-2013-4491 [MEDIUM] CVE-2013-4491 rubygem-actionpack: i18n missing translation XSS
CVE-2013-4491 rubygem-actionpack: i18n missing translation XSS
Quoting from an upcoming Ruby on Rails security advisory:
Reflective XSS Vulnerability in Ruby on Rails
There is a vulnerability in the internationalization component of Ruby on Rails. Under certain common configurations an attacker can provide specially crafted input which will execute a reflective XSS attack. This vulnerability has been assigned the CVE identifier CVE-2013-4491.
Versions Affected: 3.0.6 and all later versions.
Not affected: 3.0.5 and earlier 3.0.x versions.
Fixed Versions: 4.0.2, 3.2.16.
The root cause of this issue is a vulnerability in the i18n gem which has been assigned the identifier CVE-2013-4492. For this reason applications are also not affected if they have upgraded to the following i18n versio
http://lists.opensuse.org/opensuse-updates/2013-12/msg00093.htmlhttp://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2013/dsa-2830http://www.securityfocus.com/bid/64076https://github.com/svenfuchs/i18n/commit/92b57b1e4f84adcdcc3a375278f299274be62445https://groups.google.com/forum/message/raw?msg=ruby-security-ann/pLrh6DUw998/bLFEyIO4k_EJhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00093.htmlhttp://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2013/dsa-2830http://www.securityfocus.com/bid/64076https://github.com/svenfuchs/i18n/commit/92b57b1e4f84adcdcc3a375278f299274be62445https://groups.google.com/forum/message/raw?msg=ruby-security-ann/pLrh6DUw998/bLFEyIO4k_EJ
2013-12-07
Published