{"id":"GHSA-xxr8-833v-c7wc","summary":"Cross-site Scripting vulnerability in i18n translations helper method","details":"Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an \"html\" substring.","aliases":["CVE-2011-4319"],"modified":"2024-12-07T05:23:15.379340Z","published":"2017-10-24T18:33:38Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T22:04:59Z","nvd_published_at":"2011-11-28T11:55:09Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2011-4319"},{"type":"WEB","url":"https://github.com/rails/rails/commit/2d5b105d4bcb652550dda8b5613376d1b8beb70c"},{"type":"WEB","url":"https://github.com/rails/rails/commit/ba2d85012088fd0db0fab98b2e512c77c83cbade"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/71364"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2011-4319.yml"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/rubyonrails-security/K2HXD7c8fMU"},{"type":"WEB","url":"https://web.archive.org/web/20200228155840/http://www.securityfocus.com/bid/50722"},{"type":"WEB","url":"https://web.archive.org/web/20210307005941/http://www.securitytracker.com/id?1026342"},{"type":"WEB","url":"http://groups.google.com/group/rubyonrails-security/browse_thread/thread/2b61d70fb73c7cc5?pli=1"},{"type":"WEB","url":"http://groups.google.com/group/rubyonrails-security/msg/c65c24fbc4b6dd82?dmode=source&output=gplain"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2011/11/18/8"},{"type":"WEB","url":"http://weblog.rubyonrails.org/2011/11/18/rails-3-0-11-has-been-released"},{"type":"WEB","url":"http://weblog.rubyonrails.org/2011/11/18/rails-3-1-2-has-been-released"}],"affected":[{"package":{"name":"actionpack","ecosystem":"RubyGems","purl":"pkg:gem/actionpack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.11"}]}],"versions":["3.0.0","3.0.1","3.0.10","3.0.10.rc1","3.0.2","3.0.3","3.0.4","3.0.4.rc1","3.0.5","3.0.5.rc1","3.0.6","3.0.6.rc1","3.0.6.rc2","3.0.7","3.0.7.rc1","3.0.7.rc2","3.0.8","3.0.8.rc1","3.0.8.rc2","3.0.8.rc4","3.0.9","3.0.9.rc1","3.0.9.rc3","3.0.9.rc4","3.0.9.rc5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-xxr8-833v-c7wc/GHSA-xxr8-833v-c7wc.json"}},{"package":{"name":"actionpack","ecosystem":"RubyGems","purl":"pkg:gem/actionpack"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.0"},{"fixed":"3.1.2"}]}],"versions":["3.1.0","3.1.1","3.1.1.rc1","3.1.1.rc2","3.1.1.rc3","3.1.2.rc1","3.1.2.rc2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-xxr8-833v-c7wc/GHSA-xxr8-833v-c7wc.json"}}],"schema_version":"1.9.0"}