Description
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0589 | Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "_html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1. |
Github GHSA |
GHSA-9822-6m93-xqf4 | Rails has possible XSS Vulnerability in Action Controller |
References
History
Thu, 13 Feb 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rubyonrails
Rubyonrails rails |
|
| CPEs | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rubyonrails
Rubyonrails rails |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:41:06.380Z
Reserved: 2024-02-14T17:40:03.688Z
Link: CVE-2024-26143
Updated: 2024-08-01T23:59:32.584Z
Status : Analyzed
Published: 2024-02-27T16:15:46.800
Modified: 2025-02-13T17:13:21.617
Link: CVE-2024-26143
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA