CVE-2013-4492
Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 07 Dec 2013, 00:00
Last modified:06 Aug 2024, 16:45
Vulnerability Summary
Overall Risk (default)
low
17/100 CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
0.45% LOW
0% probability +0.07%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
07 Dec 2013, 00:00
Published
Vulnerability first disclosed
06 Aug 2024, 16:45
Last Modified
Vulnerability information updated
Description
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
CVSS Metrics
- v2.0•MEDIUM•Score: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS Trends
Current EPSS score: 0.45%• Percentile: 64%
Techniques & Countermeasures
- CWE-79•Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Affected Systems
- i18n_project•i18n
≤ 0.6.5
References (6)
- http://lists.opensuse.org/opensuse-updates/2013-12/msg00093.html
- http://www.securityfocus.com/bid/64076
- https://groups.google.com/forum/message/raw?msg=ruby-security-ann/pLrh6DUw998/bLFEyIO4k_EJ
- http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/
- http://www.debian.org/security/2013/dsa-2830
- https://github.com/svenfuchs/i18n/commit/92b57b1e4f84adcdcc3a375278f299274be62445