{"id":"GHSA-vxvp-4xwc-jpp6","summary":"activesupport Cross-site Scripting vulnerability","details":"Cross-site scripting (XSS) vulnerability in `json/encoding.rb` in Active Support in Ruby on Rails 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.","aliases":["CVE-2015-3226"],"modified":"2025-11-04T21:04:17.912261Z","published":"2017-10-24T18:33:36Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:59:02Z","nvd_published_at":"2015-07-26T22:59:05Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3226"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://groups.google.com/forum/message/raw?msg=rubyonrails-security/7VlB_pck3hU/3QZrGIaQW6cJ"},{"type":"WEB","url":"https://groups.google.com/g/rubyonrails-core/c/qBUqVlXERag/m/kuH3wQk1kxUJ"},{"type":"WEB","url":"https://web.archive.org/web/20200228033946/http://www.securityfocus.com/bid/75231"},{"type":"WEB","url":"https://web.archive.org/web/20200517005133/http://www.securitytracker.com/id/1033755"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2015/06/16/17"},{"type":"WEB","url":"http://www.debian.org/security/2016/dsa-3464"}],"affected":[{"package":{"name":"activesupport","ecosystem":"RubyGems","purl":"pkg:gem/activesupport"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.11"}]}],"versions":["4.1.0","4.1.1","4.1.10","4.1.10.rc1","4.1.10.rc2","4.1.10.rc3","4.1.10.rc4","4.1.2","4.1.2.rc1","4.1.2.rc2","4.1.2.rc3","4.1.3","4.1.4","4.1.5","4.1.6","4.1.6.rc1","4.1.6.rc2","4.1.7","4.1.7.1","4.1.8","4.1.9","4.1.9.rc1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-vxvp-4xwc-jpp6/GHSA-vxvp-4xwc-jpp6.json"}},{"package":{"name":"activesupport","ecosystem":"RubyGems","purl":"pkg:gem/activesupport"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.0"},{"fixed":"4.2.2"}]}],"versions":["4.2.0","4.2.1","4.2.1.rc1","4.2.1.rc2","4.2.1.rc3","4.2.1.rc4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-vxvp-4xwc-jpp6/GHSA-vxvp-4xwc-jpp6.json"}}],"schema_version":"1.9.0"}