CVE-2013-6416
Publication date 7 December 2013
Last updated 24 July 2024
Ubuntu priority
Description
Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| rails | ||
| ruby-actionpack-2.3 | ||
| ruby-actionpack-3.2 | ||
| ruby-activerecord-2.3 | ||
| ruby-activerecord-3.2 | ||
| ruby-activesupport-2.3 | ||
| ruby-activesupport-3.2 | ||
| ruby-rails-2.3 | ||
| ruby-rails-3.2 | ||
Notes
mdeslaur
in Oneiric+, rails package is just for transition
seth-arnold
Only affected 4.0.x and higher