Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-2931

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2011-2931
Last Modified 06 Jul 2012 12:00:00
Published 29 Aug 2011 02:55:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-2931

Summary

Cross-site scripting (XSS) vulnerability in the strip_tags helper in actionpack/lib/action_controller/vendor/html-scanner/html/node.rb in Ruby on Rails before 2.3.13, 3.0.x before 3.0.10, and 3.1.x before 3.1.0.rc5 allows remote attackers to inject arbitrary web script or HTML via a tag with an invalid name.

Vulnerable Systems

Application

  • Ruby On Rails 0.10.0

  • Ruby On Rails 0.10.1

  • Ruby On Rails 0.11.0

  • Ruby On Rails 0.11.1

  • Ruby On Rails 0.12.0

  • Ruby On Rails 0.12.1

  • Ruby On Rails 0.13.0

  • Ruby On Rails 0.13.1

  • Ruby On Rails 0.14.1

  • Ruby On Rails 0.14.2

  • Ruby On Rails 0.14.3

  • Ruby On Rails 0.14.4

  • Ruby On Rails 0.5.0

  • Ruby On Rails 0.5.5

  • Ruby On Rails 0.5.6

  • Ruby On Rails 0.5.7

  • Ruby On Rails 0.6.0

  • Ruby On Rails 0.6.5

  • Ruby On Rails 0.7.0

  • Ruby On Rails 0.8.0

  • Ruby On Rails 0.8.5

  • Ruby On Rails 0.9.0

  • Ruby On Rails 0.9.1

  • Ruby On Rails 0.9.2

  • Ruby On Rails 0.9.3

  • Ruby On Rails 0.9.4

  • Ruby On Rails 0.9.4.1

  • Ruby On Rails 1.0.0

  • Ruby On Rails 1.1.0

  • Ruby On Rails 1.1.1

  • Ruby On Rails 1.1.2

  • Ruby On Rails 1.1.3

  • Ruby On Rails 1.1.4

  • Ruby On Rails 1.1.5

  • Ruby On Rails 1.1.6

  • Ruby On Rails 1.2.0

  • Ruby On Rails 1.2.1

  • Ruby On Rails 1.2.2

  • Ruby On Rails 1.2.3

  • Ruby On Rails 1.2.4

  • Ruby On Rails 1.2.5

  • Ruby On Rails 1.2.6

  • Ruby On Rails 1.9.5

  • Ruby On Rails 2.0.0

  • Ruby On Rails 2.0.1

  • Ruby On Rails 2.0.2

  • Ruby On Rails 2.0.4

  • Ruby On Rails 2.1

  • Ruby On Rails 2.1.0

  • Ruby On Rails 2.1.1

  • Ruby On Rails 2.1.2

  • Ruby On Rails 2.2.0

  • Ruby On Rails 2.2.1

  • Ruby On Rails 2.2.2

  • Ruby On Rails 2.3.10

  • Ruby On Rails 2.3.11

  • Ruby On Rails 2.3.12

  • Ruby On Rails 2.3.2

  • Ruby On Rails 2.3.3

  • Ruby On Rails 2.3.4

  • Ruby On Rails 2.3.9

  • Ruby On Rails 3.0.0

  • Ruby On Rails 3.0.1

  • Ruby On Rails 3.0.2

  • Ruby On Rails 3.0.3

  • Ruby On Rails 3.0.4

  • Ruby On Rails 3.0.5

  • Ruby On Rails 3.0.6

  • Ruby On Rails 3.0.7

  • Ruby On Rails 3.0.8

  • Ruby On Rails 3.0.9

  • Ruby On Rails 3.1.0

  • Rubyonrails Ruby On Rails 2.0.0

  • Rubyonrails Ruby On Rails 2.0.1

  • Rubyonrails Ruby On Rails 2.0.2

  • Rubyonrails Ruby On Rails 2.0.4

  • Rubyonrails Ruby On Rails 2.1

  • Rubyonrails Ruby On Rails 2.1.0

  • Rubyonrails Ruby On Rails 2.1.1

  • Rubyonrails Ruby On Rails 2.1.2

  • Rubyonrails Ruby On Rails 2.2.0

  • Rubyonrails Ruby On Rails 2.2.1

  • Rubyonrails Ruby On Rails 2.2.2

  • Rubyonrails Ruby On Rails 2.3.10

  • Rubyonrails Ruby On Rails 2.3.11

  • Rubyonrails Ruby On Rails 2.3.12

  • Rubyonrails Ruby On Rails 2.3.2

  • Rubyonrails Ruby On Rails 2.3.3

  • Rubyonrails Ruby On Rails 2.3.4

  • Rubyonrails Ruby On Rails 2.3.9

  • Rubyonrails Ruby On Rails 3.0.0

  • Rubyonrails Ruby On Rails 3.0.1

  • Rubyonrails Ruby On Rails 3.0.10

  • Rubyonrails Ruby On Rails 3.0.2

  • Rubyonrails Ruby On Rails 3.0.3

  • Rubyonrails Ruby On Rails 3.0.4

  • Rubyonrails Ruby On Rails 3.0.5

  • Rubyonrails Ruby On Rails 3.0.6

  • Rubyonrails Ruby On Rails 3.0.7

  • Rubyonrails Ruby On Rails 3.0.8

  • Rubyonrails Ruby On Rails 3.0.9

  • Rubyonrails Ruby On Rails 3.1.0


References

CONFIRM - https://github.com/rails/rails/commit/586a944ddd4d03e66dea1093306147594748037a

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=731436

MLIST - [oss-security] 20110822 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110820 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110819 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110817 CVE request: ruby on rails flaws (4)

CONFIRM - http://weblog.rubyonrails.org/2011/8/16/ann-rails-3-1-0-rc6

MLIST - [rubyonrails-security] 20110816 XSS Vulnerability in strip_tags helper

DEBIAN - DSA-2301

SECUNIA - 45921

FEDORA - FEDORA-2011-11386

FEDORA - FEDORA-2011-11567

FEDORA - FEDORA-2011-11572


Last Updated: 27 May 2016 10:54:50