The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2011-06-30T15:26:00
Updated: 2024-08-06T22:53:17.178Z
Reserved: 2011-05-31T00:00:00
Link: CVE-2011-2197
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-06-30T15:55:01.910
Modified: 2024-11-21T01:27:47.783
Link: CVE-2011-2197
Redhat
No data.