Bug 731436 - (CVE-2011-2931) CVE-2011-2931 rubygem-actionpack: XSS vulnerability in strip_tags helper (Ruby on Rails)
CVE-2011-2931 rubygem-actionpack: XSS vulnerability in strip_tags helper (Rub...
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
: Security
Depends On: 677629 731440 731441 731448
Blocks: 732542
  Show dependency treegraph
Reported: 2011-08-17 12:40 EDT by Vincent Danen
Modified: 2016-03-04 07:22 EST (History)
10 users (show)

See Also:
Fixed In Version: rubygem-actionpack 2.3.13, rubygem-actionpack 3.0.10, rubygem-actionpack 3.1.0
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2013-01-16 04:50:04 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Vincent Danen 2011-08-17 12:40:19 EDT
An XSS vulnerability in the strip_tags helper in Ruby on Rails was reported
[1] where, using specially crafted output, an attacker can successfully inject HTML into the document, which can be used to inject arbitrary javascript into the rendered page.

This is corrected in upstream 3.0.10, 2.3.13, and 3.1.0rc5 versions.  Patches are available in the advisory [1] and in git [2].

[1] http://groups.google.com/group/rubyonrails-security/browse_thread/thread/2b9130749b74ea12
[2] https://github.com/rails/rails/commit/586a944ddd4d03e66dea1093306147594748037a
Comment 2 Vincent Danen 2011-08-17 13:22:49 EDT
This flaw is rubygem-actionpack, not rubygem-rails.
Comment 3 Vincent Danen 2011-08-17 13:26:15 EDT
Created rubygem-actionpack tracking bugs for this issue

Affects: fedora-all [bug 731448]
Affects: epel-5 [bug 677629]
Comment 5 Vincent Danen 2011-08-30 00:18:58 EDT
This issue has been assigned the name CVE-2011-2931:


Note You need to log in before you can comment on or make changes to this bug.