CVE-2009-4214: XSS
Cross-site scripting (XSS) vulnerability in the striptags function in Ruby on Rails before 2.2.s, and 2.3.x before 2.3.5, allows remote attackers to inject arbitrary web script or HTML via vectors involving non-printing ASCII characters, related to HTML::Tokenizer and actionpack/lib/actioncontroller/vendor/html-scanner/html/node.rb.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-4214?
CVE-2009-4214 has a severity rating that can allow attackers to perform cross-site scripting (XSS) attacks, exposing users to potentially malicious scripts.
How do I fix CVE-2009-4214?
To fix CVE-2009-4214, upgrade Ruby on Rails to version 2.3.5 or later to mitigate the XSS vulnerability.
What versions of Ruby on Rails are affected by CVE-2009-4214?
CVE-2009-4214 affects Ruby on Rails versions prior to 2.2.s and 2.3.x before 2.3.5.
What type of vulnerability is CVE-2009-4214?
CVE-2009-4214 is categorized as a cross-site scripting (XSS) vulnerability.
How can CVE-2009-4214 be exploited?
CVE-2009-4214 can be exploited through the injection of arbitrary web scripts or HTML via vectors involving non-printing ASCII characters.