CVE-2011-2197

Description

The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.

Risk Information

Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
EPSS Score
Exploitation Probability
0.442

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2011-2197 are fixed in Ruby-actionpack 2.3.12Windows
Vulnerabilities CVE-2011-2197 are fixed in Ruby-actionpack 3.0.8Windows
Vulnerabilities CVE-2011-2197 are fixed in Ruby-activesupport 2.3.12Windows
Vulnerabilities CVE-2011-2197 are fixed in Ruby-activesupport 3.0.8Windows
Vulnerabilities CVE-2011-2197 are fixed in Ruby-actionpack for Linux 2.3.12Linux
Vulnerabilities CVE-2011-2197 are fixed in Ruby-actionpack for Linux 3.0.8Linux
Vulnerabilities CVE-2011-2197 are fixed in Ruby-activesupport for Linux 2.3.12Linux
Vulnerabilities CVE-2011-2197 are fixed in Ruby-activesupport for Linux 3.0.8Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234