actionview Cross-site Scripting vulnerability
Moderate severity GitHub Reviewed Published Oct 24, 2017 to the GitHub Advisory Database • Updated Nov 6, 2023
Package
actionview (RubyGems)
Affected versions
>= 3.0.0, <= 3.2.22.2
>= 4.0.0, <= 4.2.7
= 5.0.0
Patched versions
3.2.22.3
4.2.7.1
5.0.0.1
Description
Published by the National Vulnerability DatabaseSep 7, 2016
Published to the GitHub Advisory Database Oct 24, 2017
Reviewed Jun 16, 2020
Last updated Nov 6, 2023
Cross-site scripting (XSS) vulnerability in Action View in Ruby on Rails 3.x before 3.2.22.3, 4.x before 4.2.7.1, and 5.x before 5.0.0.1 might allow remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers.
References