CVE-2009-4214
rails - several
EPSS 1.6%
Description
Cross-site scripting (XSS) vulnerability in the strip_tags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/action_controller/vendor/html-scanner/html/node.rb.
How to fix CVE-2009-4214
To remediate CVE-2009-4214, upgrade the affected package to a fixed version below.
- Debian/rails—upgrade to 2.2.3-2 or later
- Debian/rails—upgrade to 2.3.5-1.2+squeeze1 or later
- —upgrade to 2.2.2 or later
Is CVE-2009-4214 being exploited?
Low — EPSS is 1.6%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2.2.3-2
- from 0, < 2.3.5-1.2+squeeze1
- from 0, < 2.2.2