CVE-2015-3226: XSS
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
Other sources
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted Hash that is mishandled during JSON encoding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3226?
CVE-2015-3226 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2015-3226?
To fix CVE-2015-3226, update Active Support to version 3.2.22.5 or newer, 4.1.11 or newer, or 4.2.2 or newer.
What versions of Active Support are affected by CVE-2015-3226?
CVE-2015-3226 affects Active Support versions prior to 3.2.22.5, 4.1.11, and 4.2.2.
Can CVE-2015-3226 be exploited remotely?
Yes, CVE-2015-3226 allows remote attackers to inject arbitrary web scripts or HTML.
What systems are vulnerable to CVE-2015-3226?
CVE-2015-3226 affects Ruby on Rails 3.x and 4.x versions before their respective patched releases.