CVE-2012-3465 PUBLISHED

Reported by redhat · Published August 10, 2012

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/sanitize_helper.rb in the strip_tags helper in Ruby on Rails before 3.0.17, 3.1.x before 3.1.8, and 3.2.x before 3.2.8 allows remote attackers to inject arbitrary web script or HTML via malformed HTML markup.

Affected Products

VendorProductVersions
n/an/an/a
n/an/an/a, n/a
RubyGemsactionpack3.2.0, 0, 3.0.0.beta

Timeline

References

Open in Interactive Console →