4.3
CVSSv2

CVE-2014-2538

Published: 25/03/2014 Updated: 08/10/2015
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem prior to 1.4.0 for Ruby allows remote malicious users to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack.

Vulnerable Product Search on Vulmon Subscribe to Product

joshua peek rack-ssl 1.3.1

joshua peek rack-ssl 1.2.0

joshua peek rack-ssl 1.0.0

joshua peek rack-ssl 1.1.0

joshua peek rack-ssl 1.3.0

joshua peek rack-ssl 1.3.2

joshua peek rack-ssl 1.3.3

joshua peek rack-ssl

Vendor Advisories

Debian Bug report logs - #742186 ruby-rack-ssl: CVE-2014-2538 Package: ruby-rack-ssl; Maintainer for ruby-rack-ssl is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for ruby-rack-ssl is src:ruby-rack-ssl (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> ...
Cross-site scripting (XSS) vulnerability in lib/rack/sslrb in the rack-ssl gem before 140 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack ...