VDB
CVE-2018-16471
CVE-2018-16471
PUBLISHED
CVSS 6.099999904632568 MEDIUM
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.
EPSS 1.89% · 78.7th percentile
Risk Scores
CVSS 3.0
6.099999904632568
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
1.89%
78.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | ruby-rack | 0, 1.6.4-4 |
| Ubuntu:16.04:LTS | ruby-rack | 1.5.2-4, 1.6.4-2, 1.6.4-3 |
Timeline
- Nov 6, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 27, 2021 EPSS Score
- Mar 2, 2022 EPSS Score
- May 4, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Sep 8, 2022 EPSS Score
- Nov 10, 2022 EPSS Score
- Jan 12, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-16471 third-party-advisory
- https://ubuntu.com/security/notices/USN-4089-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-16471 third-party-advisory