This is a potential security issue, you are being redirected to https://nvd.nist.gov
NVD Dashboard
News
Email List
FAQ
Visualizations
Search & Statistics
Full Listing
Categories
Data Feeds
Vendor Comments
CVSS V3 Calculator
CVSS V2 Calculator
CPE Dictionary
CPE Search
CPE Statistics
SWID
Checklist (NCP) Repository
800-53 Controls
SCAP Validated Tools
SCAP
USGCB
Vulnerability Search
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.
Source: MITRE View Analysis Description
Source: MITRE
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.4:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.4:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.3:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.3:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.2:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.2:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc5:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.9:rc5:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.9:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc4:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.9:rc4:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.9:rc3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.9:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.9:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.8:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc4:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.8:rc4:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.8:rc3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.8:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.8:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.7:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.7:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.7:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.6:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.6:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.5:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.5:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.4:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.4:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.4:rc:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.12:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.12:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.11:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.11:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.10:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.10:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.10:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.10:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.9:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.9:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.8:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.8:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.7:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.7:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.20:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.20:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.19:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.19:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.18:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.18:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.17:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.17:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.16:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.16:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.14:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.14:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.11:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.11:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.9:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.9:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.8:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.8:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.7:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.7:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.0:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.2.0:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.5:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.5:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.4:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.4:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.2:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.2:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.1:rc3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.1:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.1:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc8:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:rc8:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc7:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:rc7:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc6:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:rc6:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc5:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:rc5:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc4:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:rc4:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:rc3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:beta1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.1.0:beta1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.13:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.13:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.13:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.13:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.12:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.12:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.12:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.12:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.10:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.10:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.10:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.10:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.2:pre:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.2:pre:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.1:pre:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.1:pre:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.0:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:rc:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.0:rc:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta4:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.0:beta4:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.0:beta3:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.0:beta2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:3.0.0:beta:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.0.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.0:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.0.0:rc2:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.0:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.0.0:rc1:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.16:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.16:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.15:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.15:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.14:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.14:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.13:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.13:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.12:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.12:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.11:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.11:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.10:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.10:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.9:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.9:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.3.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.2.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.2.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.2.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.2.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.2.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.2.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.1.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.1.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.1.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.1.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.1.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.1.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.0.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.0.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:2.0.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.2.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.1.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.9.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.9.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.2.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.2.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.2.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.2.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.2.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.2.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.1.6:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.1.5:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.1.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.1.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.1.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.1.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:1.0.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:1.0.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.14.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.14.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.14.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.14.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.14.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.14.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.14.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.14.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.13.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.13.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.13.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.13.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.12.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.12.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.12.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.12.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.11.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.11.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.11.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.11.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.10.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.10.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.10.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.10.0:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.4.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.9.4.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.9.4:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.9.3:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.9.2:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.1:*:*:*:*:*:*:*
OR *cpe:2.3:a:rubyonrails:rails:0.9.1:*:*:*:*:*:*:*
OR *cpe:2.3:o:redhat:enterprise_linux:6:*:*:*:*:*:*:*
OR *cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
El sanitize helper en lib/action_controller/vendor/html-scanner/html/sanitizer.rb en el componente Action Pack en Ruby on Rails en versiones anteriores a 2.3.18, 3.0.x y 3.1.x en versiones anteriores a 3.1.12 y 3.2.x en versiones anteriores a 3.2.13 no maneja adecuadamente codificación de caracteres : (dos puntos) en URLs, lo que hace que sea más fácil para atacantes remotos llevar a cabo ataques de secuencias de comandos en sitios cruzados (XSS) a través de un nombre de esquema manipulado, segú
La ayuda para sanitizar en lib/action_controller/vendor/html-scanner/html/sanitizer.rb en el componente Action Pack en Ruby on Rails anterior a v2.3.18, v3.0.x y v3.1.x anterior a v3.1.12, y v3.2.x anterior v3.2.13 no maneja adecuadamente la codificación:de caracteres en las URL lo que facilita a atacantes remotos llevar a cabo ataques XSS a través de un esquema manipulado como se ha demostrado añadiendo una secuencia de ":".
Configuration 1 OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.17:*:*:*:*:*:*:* (and previous) *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.11:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.12:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.10:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.14:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.13:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.16
Configuration 1 OR *cpe:2.3:o:redhat:enterprise_linux:6:*:*:*:*:*:*:* Configuration 2 OR *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.17:*:*:*:*:*:*:* (and previous) *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.11:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.12:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.10:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.14:*:*:*:*:*:*:* *cpe:2.3:a:rubyonrails:rub
http://rhn.redhat.com/errata/RHSA-2014-1863.html