Description
A cross-site scripting vulnerability flaw was found in the auto_link function in Rails before version 3.0.6.
References
https://github.com/rails/rails/blob/38df020c95beca7e12f0188cb7e18f3c37789e20/actionpack/CHANGELOG
Release NotesThird Party Advisory
https://www.openwall.com/lists/oss-security/2011/04/06/13
ExploitMailing ListThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
6.1 · Medium
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2021-10-19T14:15:08.033
3 years agoLast modified
2021-10-22T00:01:15.780
3 years ago