actionpack vulnerable to Cross-site Scripting

Description

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Not specified
Published (advisory)
2017-10-24 18:33:37 UTC
Updated
2023-08-25 19:05:48 UTC
GitHub reviewed
2020-06-16 21:18:44 UTC

EPSS Score

Score Percentile
0.71% 71.58%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Affected packages (2)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
rubygems actionpack >= 3.0.0, < 3.2.16 3.2.16
rubygems actionpack >= 4.0.0, < 4.0.2 4.0.2

References

cvelogic Threat Intelligence