CVE-2013-6416

Related Vulnerabilities: CVE-2013-6416  

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

The MITRE CVE dictionary describes this issue as:

Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

Find out more about CVE-2013-6416 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

Not vulnerable. This issue did not affect the versions of rubygem-actionpack as shipped with various Red Hat products.

CVSS v2 metrics

NOTE: The following CVSS v2 metrics and score provided are preliminary and subject to review.

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Affected Packages State

Platform Package State
Red Hat Subscription Asset Manager 1 ruby193-rubygem-actionpack Not affected
Red Hat Subscription Asset Manager 1 rubygem-actionpack Not affected
Red Hat Software Collections 1 for Red Hat Enterprise Linux ruby200-rubygem-actionpack Will not fix
Red Hat Software Collections 1 for Red Hat Enterprise Linux ruby193-rubygem-actionpack Not affected
Red Hat Satellite 6 ruby193-rubygem-actionpack Not affected
Red Hat OpenShift Enterprise 1 ruby193-rubygem-actionpack Not affected
Red Hat Enterprise Linux OpenStack Platform 4.0 ruby193-rubygem-actionpack Not affected
Red Hat Enterprise Linux OpenStack Platform 3.0 ruby193-rubygem-actionpack Not affected