CVE-2017-1002201
published 2019-10-15CVE-2017-1002201: In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like " ' must be escaped properly. In this…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.45%
70.8th percentile
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ruby-haml | < ruby-haml 5.0.4-1 (bookworm) | ruby-haml 5.0.4-1 (bookworm) |
| haml | haml | < 5.0.0 | 5.0.0 |
| haml | haml | >= 0 < 5.0.0 | 5.0.0 |
| http | haml.info_haml | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2017-1002201: ruby-haml - In haml versions prior to version 5.0.0.beta.2, when using user input to perform...
vendor_debian·2017·CVSS 6.1
CVE-2017-1002201 [MEDIUM] CVE-2017-1002201: ruby-haml - In haml versions prior to version 5.0.0.beta.2, when using user input to perform...
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
Scope: local
bookworm: resolved (fixed in 5.0.4-1)
bullseye: resolved (fixed in 5.0.4-1)
forky: resolved (fixed in 5.0.4-1)
sid: resolved (fixed in 5.0.4-1)
trixie: resolved (fixed in 5.0.4-1)
OSV
Haml vulnerable to cross-site scripting
osv·2019-10-21
CVE-2017-1002201 [MEDIUM] Haml vulnerable to cross-site scripting
Haml vulnerable to cross-site scripting
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like ` " '` must be escaped properly. In this case, the `'` character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
GHSA
Haml vulnerable to cross-site scripting
ghsa·2019-10-21
CVE-2017-1002201 [MEDIUM] CWE-79 Haml vulnerable to cross-site scripting
Haml vulnerable to cross-site scripting
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like ` " '` must be escaped properly. In this case, the `'` character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
OSV
CVE-2017-1002201: In haml versions prior to version 5
osv·2019-10-15·CVSS 6.1
CVE-2017-1002201 [MEDIUM] CVE-2017-1002201: In haml versions prior to version 5
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional attributes, potentially executing code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/haml/haml/commit/18576ae6e9bdcb4303fdbe6b3199869d289d67c2https://lists.debian.org/debian-lts-announce/2019/11/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00028.htmlhttps://security.gentoo.org/glsa/202007-27https://snyk.io/vuln/SNYK-RUBY-HAML-20362https://github.com/haml/haml/commit/18576ae6e9bdcb4303fdbe6b3199869d289d67c2https://lists.debian.org/debian-lts-announce/2019/11/msg00007.htmlhttps://lists.debian.org/debian-lts-announce/2021/12/msg00028.htmlhttps://security.gentoo.org/glsa/202007-27https://snyk.io/vuln/SNYK-RUBY-HAML-20362
2019-10-15
Published