Sha256: 29c82d7b0089ba2f260e6f3d623f0b9f83591b6c3ff1b3913a79c53124558df4

Contents?: true

Size: 674 Bytes

Versions: 1

Compression:

Stored size: 674 Bytes

Contents

--- 
gem: activesupport
framework: rails
cve: 2012-3464
osvdb: 84516
url: https://nvd.nist.gov/vuln/detail/CVE-2012-3464
title: Ruby on Rails HTML Escaping Code XSS
date: 2012-08-09

description: |
  Ruby on Rails contains a flaw that allows a remote cross-site scripting (XSS)
  attack. This flaw exists because the HTML escaping code functionality does
  not properly escape a single quote character. This may allow a user to create
  a specially crafted request that would execute arbitrary script code in a
  user's browser within the trust relationship between their browser and the
  server.

cvss_v2: 4.3

patched_versions: 
  - ~> 3.0.17
  - ~> 3.1.8
  - ">= 3.2.8"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/activesupport/CVE-2012-3464.yml