The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.
Metrics
No CVSS v4.0
No CVSS v3.1
No CVSS v3.0
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Redhat |
|
Rhel Sam |
|
Rubyonrails |
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
Configuration 5 [-]
|
Package | CPE | Advisory | Released Date |
---|---|---|---|
Red Hat Subscription Asset Manager 1.4 | |||
katello-0:1.4.3.28-1.el6sam_splice | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-actionmailer-1:3.2.17-1.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-actionpack-1:3.2.17-6.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-activemodel-1:3.2.17-1.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-activerecord-1:3.2.17-5.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-activeresource-1:3.2.17-1.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-activesupport-1:3.2.17-2.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-i18n-0:0.6.9-1.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-mail-0:2.5.4-1.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-rack-1:1.4.5-3.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-rails-1:3.2.17-1.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
ruby193-rubygem-railties-1:3.2.17-1.el6sam | cpe:/a:rhel_sam:1.4::el6 | RHSA-2014:1863 | 2014-11-17T00:00:00Z |
RHEL 6 Version of OpenShift Enterprise | |||
ruby193-rubygem-actionpack-1:3.2.8-5.el6 | cpe:/a:redhat:openshift:1::el6 | RHSA-2013:0698 | 2013-04-02T00:00:00Z |
rubygem-actionpack-1:3.0.13-8.el6op | cpe:/a:redhat:openshift:1::el6 | RHSA-2013:0698 | 2013-04-02T00:00:00Z |
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-03-19T22:00:00
Updated: 2024-08-06T15:20:35.190Z
Reserved: 2013-02-19T00:00:00
Link: CVE-2013-1857
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2013-03-19T22:55:01.087
Modified: 2019-08-08T15:42:45.623
Link: CVE-2013-1857
Redhat