{"id":"GHSA-w37c-q653-qg95","summary":"actionpack Cross-site Scripting vulnerability","details":"Cross-site scripting (XSS) vulnerability in the simple_format helper in `actionpack/lib/action_view/helpers/text_helper.rb` in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.","aliases":["CVE-2013-6416"],"modified":"2024-12-03T06:02:44.626274Z","published":"2017-10-24T18:33:36Z","database_specific":{"github_reviewed_at":"2020-06-16T21:59:19Z","nvd_published_at":"2013-12-07T00:55:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-6416"},{"type":"WEB","url":"https://github.com/rails/rails/commit/4b4f5847f64f81c961625e647711ef9f6ad1a454"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2013-6416.yml"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/ruby-security-ann/5ZI1-H5OoIM"},{"type":"WEB","url":"https://groups.google.com/forum/message/raw?msg=ruby-security-ann/5ZI1-H5OoIM/ZNq4FoR2GnIJ"},{"type":"WEB","url":"https://web.archive.org/web/20200228165109/http://www.securityfocus.com/bid/64071"},{"type":"WEB","url":"http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released"}],"affected":[{"package":{"name":"actionpack","ecosystem":"RubyGems","purl":"pkg:gem/actionpack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.2"}]}],"versions":["4.0.0","4.0.1","4.0.1.rc1","4.0.1.rc2","4.0.1.rc3","4.0.1.rc4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-w37c-q653-qg95/GHSA-w37c-q653-qg95.json"}}],"schema_version":"1.9.0"}