CVE-2011-4319: XSS
Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the railsxss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4319?
CVE-2011-4319 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-4319?
You can fix CVE-2011-4319 by upgrading to Ruby on Rails version 3.0.11 or later, or 3.1.2 or later.
Which versions of Ruby on Rails are affected by CVE-2011-4319?
Ruby on Rails versions 3.0.x before 3.0.11, 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x are affected.
What types of attacks can exploit CVE-2011-4319?
CVE-2011-4319 can be exploited through cross-site scripting (XSS) to inject arbitrary web scripts or HTML.
Is there a workaround for CVE-2011-4319 if I cannot upgrade?
There is no official workaround for CVE-2011-4319; upgrading to the fixed versions is recommended.