VDB
CVE-2011-2197
CVE-2011-2197
PUBLISHED
CVSS 9.300000190734863 CRITICAL
The cross-site scripting (XSS) prevention feature in Ruby on Rails 2.x before 2.3.12, 3.0.x before 3.0.8, and 3.1.x before 3.1.0.rc2 does not properly handle mutation of safe buffers, which makes it easier for remote attackers to conduct XSS attacks via crafted strings to an application that uses a problematic string method, as demonstrated by the sub method.
EPSS 0.44% · 63.6th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.44%
63.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| RubyGems | activesupport | 2.0.0, 3.0.0 |
| rubyonrails | rails | 2.0.0, 2.0.2, 2.0.4 |
| n/a | n/a | n/a |
| rubyonrails | ruby_on_rails | 3.0.4 |
| RubyGems | actionpack | 3.0.0, 2.0.0 |
Timeline
- Jun 30, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- [rubyonrails-security] 20110607 Potential XSS Vulnerability in Ruby on Rails Applications mailing-list
- FEDORA-2011-8494 vendor-advisory
- FEDORA-2011-8580 vendor-advisory
- http://weblog.rubyonrails.org/2011/6/8/potential-xss-vulnerability-in-ruby-on-rails-applications url
- 44789 third-party-advisory
- [oss-security] 20110609 CVE Request: Ruby on Rails 3/rails_xss XSS mailing-list
- [oss-security] 20110613 Re: CVE Request: Ruby on Rails 3/rails_xss XSS mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2011-2197 advisory
- https://github.com/rails/rails/commit/53a2c0baf2b128dd4808eca313256f6f4bb8c4cd url
- https://github.com/rails/rails/commit/ed3796434af6069ced6a641293cf88eef3b284da url
- https://gist.github.com/NZKoz/b2ceb626fc2bcdfe497f url
- https://github.com/rails/rails package
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activesupport/CVE-2011-2197.yml url