CVE-2023-23913
published 2025-01-09CVE-2023-23913: There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the…
PriorityP430medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
EPSS
0.64%
46.7th percentile
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2:6.1.7.3+dfsg-1 (bookworm) | rails 2:6.1.7.3+dfsg-1 (bookworm) |
| rails | actionview | >= 5.1.0 < 6.1.7.3 | 6.1.7.3 |
| rails | actionview | >= 7.0.0 < 7.0.4.3 | 7.0.4.3 |
| rails | rails-ujs | >= 6.1.7.3 < 6.1.7.3 | 6.1.7.3 |
| rails | rails-ujs | >= 7.0.4.3 < 7.0.4.3 | 7.0.4.3 |
| rubyonrails | rails | >= 0 < 2:6.0.3.7+dfsg-2+deb11u2 | 2:6.0.3.7+dfsg-2+deb11u2 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.7.3+dfsg-1 | 2:6.1.7.3+dfsg-1 |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
ghsa6.3MEDIUM
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-23913: There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the
osv·2025-01-09·CVSS 6.3
CVE-2023-23913 [MEDIUM] CVE-2023-23913: There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.
OSV
rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
osv·2023-06-09·CVSS 6.3
CVE-2023-23913 [MEDIUM] rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
NOTE: rails-ujs is part of Rails/actionview since 5.1.0.
There is a potential DOM based cross-site scripting issue in rails-ujs
which leverages the Clipboard API to target HTML elements that are
assigned the contenteditable attribute. This has the potential to
occur when pasting malicious HTML content from the clipboard that
includes a data-method, data-remote or data-disable-with attribute.
This vulnerability has been assigned the CVE identifier CVE-2023-23913.
Not affected: = 5.1.0
Fixed Versions: 6.1.7.3, 7.0.4.3
Impact
If the specified malicious HTML clipboard content is provided to a
contenteditable element, this could result in the arbitrary execution
of javascript on the origin in question.
Re
GHSA
rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
ghsa·2023-06-09·CVSS 6.3
CVE-2023-23913 [MEDIUM] CWE-79 rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
NOTE: rails-ujs is part of Rails/actionview since 5.1.0.
There is a potential DOM based cross-site scripting issue in rails-ujs
which leverages the Clipboard API to target HTML elements that are
assigned the contenteditable attribute. This has the potential to
occur when pasting malicious HTML content from the clipboard that
includes a data-method, data-remote or data-disable-with attribute.
This vulnerability has been assigned the CVE identifier CVE-2023-23913.
Not affected: = 5.1.0
Fixed Versions: 6.1.7.3, 7.0.4.3
Impact
If the specified malicious HTML clipboard content is provided to a
contenteditable element, this could result in the arbitrary execution
of javascript on the origin in question.
Re
Red Hat
rails: DOM Based Cross-site Scripting in rails-ujs for contenteditable HTML Elements
vendor_redhat·2023-03-20·CVSS 6.3
CVE-2023-23913 [MEDIUM] CWE-79 rails: DOM Based Cross-site Scripting in rails-ujs for contenteditable HTML Elements
rails: DOM Based Cross-site Scripting in rails-ujs for contenteditable HTML Elements
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.
A flaw was found in Rails. rails-ujs may allow an attacker to perform Cross-Site Scripting (XSS), which could lead to stolen information, phishing attacks, and other types of attacks.
Package: rails (Red Hat 3scale API Management Platform 2) - Will not fix
Debian
CVE-2023-23913: rails - There is a potential DOM based cross-site scripting issue in rails-ujs which lev...
vendor_debian·2023·CVSS 6.3
CVE-2023-23913 [MEDIUM] CVE-2023-23913: rails - There is a potential DOM based cross-site scripting issue in rails-ujs which lev...
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.
Scope: local
bookworm: resolved (fixed in 2:6.1.7.3+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u2)
forky: resolved (fixed in 2:6.1.7.3+dfsg-1)
sid: resolved (fixed in 2:6.1.7.3+dfsg-1)
trixie: resolved (fixed in 2:6.1.7.3+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1033263https://discuss.rubyonrails.org/t/cve-2023-23913-dom-based-cross-site-scripting-in-rails-ujs-for-contenteditable-html-elements/82468https://github.com/rails/rails/commit/5037a13614d71727af8a175063bcf6ba1a74bdbdhttps://security.netapp.com/advisory/ntap-20240605-0007/https://www.debian.org/security/2023/dsa-5389
2025-01-09
Published