{"id":"GHSA-wmq2-jc9m-xp4m","summary":"Cross-site Scripting in in JRuby","details":"The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.","aliases":["CVE-2010-1330"],"modified":"2023-11-08T03:56:55.599271Z","published":"2022-05-02T06:21:36Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-01T22:47:20Z","nvd_published_at":"2012-11-23T19:55:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1330"},{"type":"WEB","url":"https://bugs.gentoo.org/show_bug.cgi?id=317435"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=750306"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/80277"},{"type":"PACKAGE","url":"https://github.com/jruby/jruby"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2011-1456.html"},{"type":"WEB","url":"http://secunia.com/advisories/46891"},{"type":"WEB","url":"http://www.jruby.org/2010/04/26/jruby-1-4-1-xss-vulnerability.html"},{"type":"WEB","url":"http://www.osvdb.org/77297"}],"affected":[{"package":{"name":"org.jruby:jruby-core","ecosystem":"Maven","purl":"pkg:maven/org.jruby/jruby-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.4.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-wmq2-jc9m-xp4m/GHSA-wmq2-jc9m-xp4m.json"}}],"schema_version":"1.9.0"}