4.3
CVSSv2

CVE-2015-3226

Published: 26/07/2015 Updated: 08/08/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x prior to 4.1.11 and 4.2.x prior to 4.2.2 allows remote malicious users to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.

Vulnerable Product Search on Vulmon Subscribe to Product

rubyonrails rails 4.1.7

rubyonrails rails 4.1.6

rubyonrails rails 3.2.17

rubyonrails rails 3.2.16

rubyonrails rails 4.2.1

rubyonrails rails 4.1.3

rubyonrails rails 4.1.2

rubyonrails rails 3.2.12

rubyonrails rails 3.2.11

rubyonrails rails 3.2.8

rubyonrails rails 3.2.7

rubyonrails rails 3.2.0

rubyonrails rails 3.1.0

rubyonrails rails 3.2.4

rubyonrails rails 3.2.3

rubyonrails rails 4.1.5

rubyonrails rails 4.1.4

rubyonrails rails 3.2.15

rubyonrails ruby on rails 3.2.14

rubyonrails rails 3.2.13

rubyonrails rails 3.2.6

rubyonrails rails 3.2.5

rubyonrails rails 3.0.0

rubyonrails rails 4.2.0

rubyonrails rails 4.1.8

rubyonrails rails 4.1.1

rubyonrails rails 4.1.0

rubyonrails rails 3.2.10

rubyonrails rails 3.2.9

rubyonrails rails 3.2.2

rubyonrails rails 3.2.1

Vendor Advisories

Debian Bug report logs - #790486 rails: CVE-2015-3226: XSS in ActiveSupport::JSONencode Package: src:rails; Maintainer for src:rails is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 29 Jun 2015 18:36:01 UTC Sever ...
Debian Bug report logs - #790487 rails: CVE-2015-3227: Possible Denial of Service attack in Active Support Package: src:rails; Maintainer for src:rails is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 29 Jun 2015 1 ...
Multiple security issues have been discovered in the Ruby on Rails web application development framework, which may result in denial of service, cross-site scripting, information disclosure or bypass of input validation For the stable distribution (jessie), these problems have been fixed in version 2:418-1+deb8u1 For the unstable distribution ( ...
Cross-site scripting (XSS) vulnerability in json/encodingrb in Active Support in Ruby on Rails 3x and 41x before 4111 and 42x before 422 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding ...