{"id":"CVE-2024-32463","summary":"phlex makes Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `\u003ca\u003e` tags","details":"phlex is an open source framework for building object-oriented views in Ruby. There is a potential cross-site scripting (XSS) vulnerability that can be exploited via maliciously crafted user data. The filter to detect and prevent the use of the `javascript:` URL scheme in the `href` attribute of an `\u003ca\u003e` tag could be bypassed with tab `\\t` or newline `\\n` characters between the characters of the protocol, e.g. `java\\tscript:`. This vulnerability is fixed in 1.10.1, 1.9.2, 1.8.3, 1.7.2, 1.6.3, 1.5.3, and 1.4.2. Configuring a Content Security Policy that does not allow `unsafe-inline` would effectively prevent this vulnerability from being exploited.","aliases":["GHSA-g7xq-xv8c-h98c"],"modified":"2026-08-12T03:51:18.210373663Z","published":"2024-04-17T15:29:14.463Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32463.json"},"references":[{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy"},{"type":"WEB","url":"https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy#unsafe-inline"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32463.json"},{"type":"ADVISORY","url":"https://github.com/phlex-ruby/phlex/security/advisories/GHSA-g7xq-xv8c-h98c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32463"},{"type":"FIX","url":"https://github.com/phlex-ruby/phlex/commit/9e3f5b980655817993682e409cbda72956d865cb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/yippee-fun/phlex","events":[{"introduced":"215dec39f43278b1ef6761203a484602276c4f3d"},{"introduced":"5f0c9b068b50cb0f5fb8239fb0138539ff09eaa8"},{"introduced":"821834048320ed36f2e36d4be88e67e081b9b224"},{"introduced":"fc5b52dfb777999709c40edad7c23395af4621a5"},{"introduced":"41ed20fb52ec121c7ea076953df4d54d909ddd0a"},{"introduced":"c00178aeda556f8799af08ace27ceada99544bd3"},{"introduced":"a54939c318ffaf6ee7f1d3199f8e07d9c6c87605"},{"fixed":"61c03034c8c8f3e03a719b1783ee0d298442f232"},{"fixed":"169dfbfb803a96080bfaae525f4b7c23f0e6c107"},{"fixed":"57f2982a2e3350c9bd58e92bdb98820ed0e1cb4f"},{"fixed":"7d53c220878f623081389780f9c3ec0c30bc44f8"},{"fixed":"1c9f72a0ab5bc3006097400ed11de8413d99457b"},{"fixed":"175f67a4cd11609935f73cafdc923dea45f99ac7"},{"fixed":"c4056b48f2f4ece5f49d03673ecb17bdf47032c3"},{"fixed":"9e3f5b980655817993682e409cbda72956d865cb"}],"database_specific":{"extracted_events":[{"introduced":"1.10.0"},{"fixed":"1.10.1"},{"introduced":"1.9.0"},{"fixed":"1.9.2"},{"introduced":"1.8.0"},{"fixed":"1.8.3"},{"introduced":"1.7.0"},{"fixed":"1.7.2"},{"introduced":"1.6.0"},{"fixed":"1.6.3"},{"introduced":"1.5.0"},{"fixed":"1.5.3"},{"introduced":"1.4.0"},{"fixed":"1.4.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.4.1","1.5.2","1.6.2","1.7.1","1.8.2","1.9.1","1.10.0","1.4.0","1.5.1","1.6.1","1.7.0","1.8.1","1.9.0","1.8.0","1.6.0","1.5.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32463.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}]}