In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
History
No history.
Information
Published : 2020-03-19 18:15
Updated : 2024-11-21 05:33
NVD link : CVE-2020-5267
Mitre link : CVE-2020-5267
CVE.ORG link : CVE-2020-5267
JSON object : View
Products Affected
rubyonrails
- actionview
debian
- debian_linux
fedoraproject
- fedora
opensuse
- leap