Back

MEDIUM

Possible XSS vulnerability in ActionView

Published Mar 19, 2020

Description

In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.

Affected products

Remediation

Red Hat statement

Red Hat CloudForms and Satellite ship affected RubyGem actionview with methods, however, those are not vulnerable since none of those uses template string enclosed with backtick characters. A future update may fix affected RubyGem.

References (16)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Mar 19, 2020
Updated Aug 4, 2024
Reserved Jan 2, 2020

CISA Vulnrichment

No data

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Mar 19, 2020
Bugzilla 1831528

ENISA EUVD

Assigner GitHub_M
Published Mar 19, 2020
Updated Aug 4, 2024