Bug 2138957 (CVE-2022-3704) - CVE-2022-3704 rubygem-rails: XSS within Route Error Page
Summary: CVE-2022-3704 rubygem-rails: XSS within Route Error Page
Keywords:
Status: NEW
Alias: CVE-2022-3704
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2138958 2138960 2139421
Blocks: 2138140
TreeView+ depends on / blocked
 
Reported: 2022-10-31 19:04 UTC by ybuenos
Modified: 2023-07-17 14:25 UTC (History)
11 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A self cross-site scripting vulnerability was found in Ruby on Rails. This issue occurs when requesting a page that does not have a matching routing, allowing a user to create a script injection within the routing error page.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description ybuenos 2022-10-31 19:04:22 UTC
A vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is be177e4566747b73ff63fd5f529fab564e475ed4. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-212319.

https://github.com/rails/rails/issues/46244
https://vuldb.com/?id.212319
https://github.com/rails/rails/commit/be177e4566747b73ff63fd5f529fab564e475ed4

Comment 1 ybuenos 2022-10-31 19:04:53 UTC
Created rubygem-rails tracking bugs for this issue:

Affects: fedora-all [bug 2138958]


Note You need to log in before you can comment on or make changes to this bug.