Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-1857

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2013-1857
Last Modified 28 Sep 2015 11:56:53
Published 19 Mar 2013 06:55:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2013-1857

Summary

The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.

Vulnerable Systems

Operating System

  • Redhat Enterprise Linux 6

Application

  • Rubyonrails Ruby On Rails 0.10.0

  • Rubyonrails Ruby On Rails 0.10.1

  • Rubyonrails Ruby On Rails 0.11.0

  • Rubyonrails Ruby On Rails 0.11.1

  • Rubyonrails Ruby On Rails 0.12.0

  • Rubyonrails Ruby On Rails 0.12.1

  • Rubyonrails Ruby On Rails 0.13.0

  • Rubyonrails Ruby On Rails 0.13.1

  • Rubyonrails Ruby On Rails 0.14.1

  • Rubyonrails Ruby On Rails 0.14.2

  • Rubyonrails Ruby On Rails 0.14.3

  • Rubyonrails Ruby On Rails 0.14.4

  • Rubyonrails Ruby On Rails 0.5.0

  • Rubyonrails Ruby On Rails 0.5.5

  • Rubyonrails Ruby On Rails 0.5.6

  • Rubyonrails Ruby On Rails 0.5.7

  • Rubyonrails Ruby On Rails 0.6.0

  • Rubyonrails Ruby On Rails 0.6.5

  • Rubyonrails Ruby On Rails 0.7.0

  • Rubyonrails Ruby On Rails 0.8.0

  • Rubyonrails Ruby On Rails 0.8.5

  • Rubyonrails Ruby On Rails 0.9.0

  • Rubyonrails Ruby On Rails 0.9.1

  • Rubyonrails Ruby On Rails 0.9.2

  • Rubyonrails Ruby On Rails 0.9.3

  • Rubyonrails Ruby On Rails 0.9.4

  • Rubyonrails Ruby On Rails 0.9.4.1

  • Rubyonrails Ruby On Rails 1.0.0

  • Rubyonrails Ruby On Rails 1.1.0

  • Rubyonrails Ruby On Rails 1.1.1

  • Rubyonrails Ruby On Rails 1.1.2

  • Rubyonrails Ruby On Rails 1.1.3

  • Rubyonrails Ruby On Rails 1.1.4

  • Rubyonrails Ruby On Rails 1.1.5

  • Rubyonrails Ruby On Rails 1.1.6

  • Rubyonrails Ruby On Rails 1.2.0

  • Rubyonrails Ruby On Rails 1.2.1

  • Rubyonrails Ruby On Rails 1.2.2

  • Rubyonrails Ruby On Rails 1.2.3

  • Rubyonrails Ruby On Rails 1.2.4

  • Rubyonrails Ruby On Rails 1.2.5

  • Rubyonrails Ruby On Rails 1.2.6

  • Rubyonrails Ruby On Rails 1.9.5

  • Rubyonrails Ruby On Rails 2.0.0

  • Rubyonrails Ruby On Rails 2.0.1

  • Rubyonrails Ruby On Rails 2.0.2

  • Rubyonrails Ruby On Rails 2.0.4

  • Rubyonrails Ruby On Rails 2.1

  • Rubyonrails Ruby On Rails 2.1.0

  • Rubyonrails Ruby On Rails 2.1.1

  • Rubyonrails Ruby On Rails 2.1.2

  • Rubyonrails Ruby On Rails 2.2.0

  • Rubyonrails Ruby On Rails 2.2.1

  • Rubyonrails Ruby On Rails 2.2.2

  • Rubyonrails Ruby On Rails 2.3.0

  • Rubyonrails Ruby On Rails 2.3.1

  • Rubyonrails Ruby On Rails 2.3.10

  • Rubyonrails Ruby On Rails 2.3.11

  • Rubyonrails Ruby On Rails 2.3.12

  • Rubyonrails Ruby On Rails 2.3.13

  • Rubyonrails Ruby On Rails 2.3.14

  • Rubyonrails Ruby On Rails 2.3.15

  • Rubyonrails Ruby On Rails 2.3.16

  • Rubyonrails Ruby On Rails 2.3.17

  • Rubyonrails Ruby On Rails 2.3.2

  • Rubyonrails Ruby On Rails 2.3.3

  • Rubyonrails Ruby On Rails 2.3.4

  • Rubyonrails Ruby On Rails 2.3.9

  • Rubyonrails Ruby On Rails 3.0.0

  • Rubyonrails Ruby On Rails 3.0.1

  • Rubyonrails Ruby On Rails 3.0.10

  • Rubyonrails Ruby On Rails 3.0.11

  • Rubyonrails Ruby On Rails 3.0.12

  • Rubyonrails Ruby On Rails 3.0.13

  • Rubyonrails Ruby On Rails 3.0.14

  • Rubyonrails Ruby On Rails 3.0.16

  • Rubyonrails Ruby On Rails 3.0.17

  • Rubyonrails Ruby On Rails 3.0.18

  • Rubyonrails Ruby On Rails 3.0.19

  • Rubyonrails Ruby On Rails 3.0.2

  • Rubyonrails Ruby On Rails 3.0.20

  • Rubyonrails Ruby On Rails 3.0.3

  • Rubyonrails Ruby On Rails 3.0.4

  • Rubyonrails Ruby On Rails 3.0.5

  • Rubyonrails Ruby On Rails 3.0.6

  • Rubyonrails Ruby On Rails 3.0.7

  • Rubyonrails Ruby On Rails 3.0.8

  • Rubyonrails Ruby On Rails 3.0.9

  • Rubyonrails Ruby On Rails 3.1.0

  • Rubyonrails Ruby On Rails 3.1.1

  • Rubyonrails Ruby On Rails 3.1.10

  • Rubyonrails Ruby On Rails 3.1.11

  • Rubyonrails Ruby On Rails 3.1.2

  • Rubyonrails Ruby On Rails 3.1.3

  • Rubyonrails Ruby On Rails 3.1.4

  • Rubyonrails Ruby On Rails 3.1.5

  • Rubyonrails Ruby On Rails 3.1.6

  • Rubyonrails Ruby On Rails 3.1.7

  • Rubyonrails Ruby On Rails 3.1.8

  • Rubyonrails Ruby On Rails 3.1.9

  • Rubyonrails Ruby On Rails 3.2.0

  • Rubyonrails Ruby On Rails 3.2.1

  • Rubyonrails Ruby On Rails 3.2.10

  • Rubyonrails Ruby On Rails 3.2.11

  • Rubyonrails Ruby On Rails 3.2.12

  • Rubyonrails Ruby On Rails 3.2.2

  • Rubyonrails Ruby On Rails 3.2.3

  • Rubyonrails Ruby On Rails 3.2.4

  • Rubyonrails Ruby On Rails 3.2.5

  • Rubyonrails Ruby On Rails 3.2.6

  • Rubyonrails Ruby On Rails 3.2.7

  • Rubyonrails Ruby On Rails 3.2.8

  • Rubyonrails Ruby On Rails 3.2.9


References

MLIST - [rubyonrails-security] 20130318 [CVE-2013-1857] XSS Vulnerability in the `sanitize` helper of Ruby on Rails

CONFIRM - http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/

REDHAT - RHSA-2013:0698

SUSE - openSUSE-SU-2013:0662

SUSE - openSUSE-SU-2013:0661

CONFIRM - http://support.apple.com/kb/HT5784

APPLE - APPLE-SA-2013-06-04-1

APPLE - APPLE-SA-2013-10-22-5

SUSE - openSUSE-SU-2014:0019

REDHAT - RHSA-2014:1863


Last Updated: 27 May 2016 11:02:06