Publish GHSA-7g65-ghrg-hpf5

This commit is contained in:
advisory-database[bot]
2025-01-21 15:23:05 +00:00
parent 846189e0b6
commit 9789500935
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7g65-ghrg-hpf5",
"modified": "2023-01-23T16:30:29Z",
"modified": "2025-01-21T15:21:13Z",
"published": "2017-10-24T18:33:37Z",
"aliases": [
"CVE-2012-3465"
],
"summary": "actionpack Cross-site Scripting vulnerability",
"details": "Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/sanitize_helper.rb` in the `strip_tags` helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.",
"details": "Cross-site scripting (XSS) vulnerability in `actionpack/lib/action_view/helpers/sanitize_helper.rb` in the `strip_tags` helper in Ruby on Rails before 2.3.16, 3.0.x before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.",
"severity": [],
"affected": [
{
@@ -20,7 +20,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
"introduced": "3.0.0.beta"
},
{
"fixed": "3.0.17"
@@ -66,6 +66,25 @@
]
}
]
},
{
"package": {
"ecosystem": "RubyGems",
"name": "actionpack"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.3.16"
}
]
}
]
}
],
"references": [
@@ -73,10 +92,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3465"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/cf48c9c7dcbef8543171f7f7de8d3d9a16b58e77"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/e91e4e8bbee12ce1496bf384c04da6be296b687a"
},
{
"type": "PACKAGE",
"url": "https://github.com/rails/rails"
},
{
"type": "WEB",
"url": "https://groups.google.com/group/rubyonrails-security/msg/7fbb5392d4d282b5?dmode=source&output=gplain"