-
Notifications
You must be signed in to change notification settings - Fork 1
CVE-2011-4319 Medium Severity Vulnerability detected by WhiteSource #106
Description
CVE-2011-4319 - Medium Severity Vulnerability
Vulnerable Library - rails-3.0.9.gem
path: /ridemo/Gemfile.lock
Library home page: http://rubygems.org/gems/rails-3.0.9.gem
Dependency Hierarchy:
- ❌ rails-3.0.9.gem (Vulnerable Library)
Vulnerability Details
Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.
Publish Date: 2011-11-28
URL: CVE-2011-4319
Suggested Fix
Type: Upgrade version
Origin: http://xforce.iss.net/xforce/xfdb/71364
Release Date: 2017-12-31
Fix Resolution: Upgrade to the latest version of Ruby on Rails (3.0.11 or 3.1.2 or later), available from the Ruby on Rails Web site. See References.
Step up your Open Source Security Game with WhiteSource here