Sha256: 71d1a830fd07e8d671172b8d84ee1dec83709d14964b66fbcc0a20d3cd9ef787
Contents?: true
Size: 624 Bytes
Versions: 1
Compression:
Stored size: 624 Bytes
Contents
--- gem: actionpack framework: rails cve: 2013-1857 osvdb: 91454 url: https://nvd.nist.gov/vuln/detail/CVE-2013-1857 title: XSS Vulnerability in the `sanitize` helper of Ruby on Rails date: 2013-03-19 description: | The sanitize helper in Ruby on Rails is designed to filter HTML and remove all tags and attributes which could be malicious. The code which ensured that URLs only contain supported protocols contained several bugs which could allow an attacker to embed a tag containing a URL which executes arbitrary javascript code. cvss_v2: 4.3 patched_versions: - ~> 2.3.18 - ~> 3.1.12 - ">= 3.2.13"
Version data entries
1 entries across 1 versions & 1 rubygems
Version | Path |
---|---|
bundler-audit-0.7.0.1 | data/ruby-advisory-db/gems/actionpack/CVE-2013-1857.yml |