CVE-2015-3226
published 2015-07-26CVE-2015-3226: Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.78%
84.9th percentile
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2:4.2.4-2 (bookworm) | rails 2:4.2.4-2 (bookworm) |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
activesupport Cross-site Scripting vulnerability
ghsa·2017-10-24
CVE-2015-3226 [MEDIUM] CWE-79 activesupport Cross-site Scripting vulnerability
activesupport Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in `json/encoding.rb` in Active Support in Ruby on Rails 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
OSV
activesupport Cross-site Scripting vulnerability
osv·2017-10-24
CVE-2015-3226 [MEDIUM] activesupport Cross-site Scripting vulnerability
activesupport Cross-site Scripting vulnerability
Cross-site scripting (XSS) vulnerability in `json/encoding.rb` in Active Support in Ruby on Rails 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
OSV
CVE-2015-3226: Cross-site scripting (XSS) vulnerability in json/encoding
osv·2015-07-26·CVSS 4.3
CVE-2015-3226 [MEDIUM] CVE-2015-3226: Cross-site scripting (XSS) vulnerability in json/encoding
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
Red Hat
rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode
vendor_redhat·2015-06-16·CVSS 4.3
CVE-2015-3226 [MEDIUM] CWE-79 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode
rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
Package: ruby193-rubygem-activesupport (CloudForms Management Engine 5) - Will not fix
Package: rh-ror41-rubygem-activesupport (Red Hat Software Collections) - Will not fix
Package: ror40-rubygem-activesupport (Red Hat Software Collections) - Not affected
Package: ruby193-rubygem-activesupport (Red Hat Software Collections) - Will not fix
Package: ruby193-rubygem-activesupport (Red Hat Subscription Asset Manager) - Will not fix
Package: rubygem-act
Debian
CVE-2015-3226: rails - Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support i...
vendor_debian·2015·CVSS 4.3
CVE-2015-3226 [MEDIUM] CVE-2015-3226: rails - Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support i...
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
Scope: local
bookworm: resolved (fixed in 2:4.2.4-2)
bullseye: resolved (fixed in 2:4.2.4-2)
forky: resolved (fixed in 2:4.2.4-2)
sid: resolved (fixed in 2:4.2.4-2)
trixie: resolved (fixed in 2:4.2.4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode [fedora-all]
bugzilla·2015-07-31·CVSS 4.3
CVE-2015-3226 [MEDIUM] CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode [fedora-all]
CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode [epel-all]
bugzilla·2015-07-31·CVSS 4.3
CVE-2015-3226 [MEDIUM] CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode [epel-all]
CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode
bugzilla·2015-06-16·CVSS 4.3
CVE-2015-3226 [MEDIUM] CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode
CVE-2015-3226 rubygem-activesupport: XSS Vulnerability in ActiveSupport::JSON.encode
There is an XSS vulnerability in the ActiveSupport::JSON.encode method in Ruby on Rails.
When a `Hash` containing user-controlled data is encode as JSON (either through
`Hash#to_json` or `ActiveSupport::JSON.encode`), Rails does not perform adequate
escaping that matches the guarantee implied by the `escape_html_entities_in_json`
option (which is enabled by default). If this resulting JSON string is subsequently
inserted directly into an HTML page, the page will be vulnerable to XSS attacks.
For example, the following code snippet is vulnerable to this attack:
Similarly, the following is also vulnerable:
var data = ;
Workarounds
To work around this problem add an initializer with the following co
HackerOne
JSON keys are not properly escaped
hackerone·2015-06-16·CVSS 7.2
[HIGH] JSON keys are not properly escaped
JSON keys are not properly escaped
Rails does not escape hash keys properly in `to_json` when generating json.
Values are escaped as expected
```ruby
irb(main):001:0> {"a"=>"<>"}.to_json
=> "{\"a\":\"\\u003c\\u003e\"}"
```
However keys are not:
```ruby
irb(main):002:0> {"<>"=>"a"}.to_json
=> "{\"<>\":\"a\"}"
```
This is because the `json` gem calls `.to_s` on the keys [here](https://github.com/flori/json/blob/259dee6c9bdda08ed0c1fc2e69bfbb2d377faba0/ext/json/ext/generator/generator.c#L738) which transforms the `EscapedString` back into a simple `String` so it doesn't go through the escaping process that values go through [here](https://github.com/EiNSTeiN-/rails/blob/3820788e4c2825dd77c779ba5b3bc29689e04e1d/activesupport/lib/active_support/json/encoding.rb#L54-L60).
**Security conside
http://openwall.com/lists/oss-security/2015/06/16/17http://www.debian.org/security/2016/dsa-3464http://www.securityfocus.com/bid/75231http://www.securitytracker.com/id/1033755https://groups.google.com/forum/message/raw?msg=rubyonrails-security/7VlB_pck3hU/3QZrGIaQW6cJhttp://openwall.com/lists/oss-security/2015/06/16/17http://www.debian.org/security/2016/dsa-3464http://www.securityfocus.com/bid/75231http://www.securitytracker.com/id/1033755https://groups.google.com/forum/message/raw?msg=rubyonrails-security/7VlB_pck3hU/3QZrGIaQW6cJ
2015-07-26
Published