CVE-2013-6416
published 2013-12-07CVE-2013-6416: Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.96%
78.1th percentile
Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 4.0.0 < 4.0.2 | 4.0.2 |
| debian | rails | — | — |
| rubyonrails | rails | <= 4.0.1 | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
actionpack Cross-site Scripting vulnerability
osv·2017-10-24
CVE-2013-6416 [MEDIUM] actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in the simple_format helper in `actionpack/lib/action_view/helpers/text_helper.rb` in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
GHSA
actionpack Cross-site Scripting vulnerability
ghsa·2017-10-24
CVE-2013-6416 [MEDIUM] CWE-79 actionpack Cross-site Scripting vulnerability
actionpack Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in the simple_format helper in `actionpack/lib/action_view/helpers/text_helper.rb` in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Red Hat
rubygem-actionpack: simple_format XSS
vendor_redhat·2013-12-03·CVSS 4.3
CVE-2013-6416 [MEDIUM] CWE-79 rubygem-actionpack: simple_format XSS
rubygem-actionpack: simple_format XSS
Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Statement: Not vulnerable. This issue did not affect the versions of rubygem-actionpack as shipped with various Red Hat products.
Package: ruby193-rubygem-actionpack (CloudForms Management Engine 5) - Not affected
Package: ruby193-rubygem-actionpack (OpenShift Enterprise 1) - Not affected
Package: ruby193-rubygem-actionpack (Red Hat OpenStack Platform 3) - Not affected
Package: ruby193-rubygem-actionpack (Red Hat OpenStack Platform 4) - Not affected
Package: ruby193-rubygem-actionpack (Red Hat Satelli
Debian
CVE-2013-6416: rails - Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpa...
vendor_debian·2013·CVSS 4.3
CVE-2013-6416 [MEDIUM] CVE-2013-6416: rails - Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpa...
Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.securityfocus.com/bid/64071https://groups.google.com/forum/message/raw?msg=ruby-security-ann/5ZI1-H5OoIM/ZNq4FoR2GnIJhttp://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.securityfocus.com/bid/64071https://groups.google.com/forum/message/raw?msg=ruby-security-ann/5ZI1-H5OoIM/ZNq4FoR2GnIJ
2013-12-07
Published