CVE-2013-4492: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
References
- lists.opensuse.org/opensuse-updates/2013-12/msg00093.html
- weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/
- www.debian.org/security/2013/dsa-2830
- www.securityfocus.com/bid/64076
- github.com/svenfuchs/i18n/commit/92b57b1e4f84adcdcc3a375278f299274be62445
- groups.google.com/forum/message/raw?msg=ruby-security-ann/pLrh6DUw998/bLFEyIO4k_EJ
- nvd.nist.gov/vuln/detail/CVE-2013-4492
Detect and mitigate CVE-2013-4492 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →