CVE-2013-4491

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-4491 at MITRE

Description

Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.

NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)

SUSE information

SUSE Bugzilla entries: 846239, 853625, 854166, 854786

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Lifecycle Management Server 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
Patchnames:
sleslms13-rubygem-actionpack-3_2
SUSE Linux Enterprise High Availability Extension 11 SP3
  • hawk >= 0.6.1-0.17.1
  • hawk-templates >= 0.6.1-0.17.1
Patchnames:
slehasp3-hawk
SUSE Linux Enterprise Software Development Kit 11 SP2
  • rubygem-actionpack-2_3 >= 2.3.17-0.13.2
Patchnames:
sdksp2-rubygem-actionpack-2_3
SUSE Studio Onsite 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
  • susestudio >= 1.3.7-0.17.1
  • susestudio-admin_en >= 11.3-0.15.1
  • susestudio-admin_en-pdf >= 11.3-0.15.1
  • susestudio-bundled-packages >= 1.3.7-0.17.1
  • susestudio-common >= 1.3.7-0.17.1
  • susestudio-runner >= 1.3.7-0.17.1
  • susestudio-sid >= 1.3.7-0.17.1
  • susestudio-ui-server >= 1.3.7-0.17.1
Patchnames:
slestso13-rubygem-actionpack-3_2
slestso13-susestudio-137-201404
SUSE WebYast 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
Patchnames:
slewyst13-rubygem-actionpack-3_2
SUSE Cloud 2.0
SUSE Linux Enterprise Software Development Kit 11 SP3
  • rubygem-actionpack-2_3 >= 2.3.17-0.13.1
Builds
SAT Patch Nr: 8698
SUSE Linux Enterprise High Availability Extension 11 SP3
  • hawk >= 0.6.1-0.17.1
  • hawk-templates >= 0.6.1-0.17.1
Builds
SAT Patch Nr: 9208
SUSE Lifecycle Management Server 1.3
SUSE Studio Onsite 1.3
WebYaST 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
Builds
SAT Patch Nr: 8667
SUSE Studio Onsite 1.3
  • susestudio >= 1.3.7-0.17.1
  • susestudio-admin_en >= 11.3-0.15.1
  • susestudio-admin_en-pdf >= 11.3-0.15.1
  • susestudio-bundled-packages >= 1.3.7-0.17.1
  • susestudio-common >= 1.3.7-0.17.1
  • susestudio-runner >= 1.3.7-0.17.1
  • susestudio-sid >= 1.3.7-0.17.1
  • susestudio-ui-server >= 1.3.7-0.17.1
Builds
SAT Patch Nr: 9308
SUSE Linux Enterprise Software Development Kit 11 SP2
  • rubygem-actionpack-2_3 >= 2.3.17-0.13.2
Builds
SAT Patch Nr: 8702
openSUSE 12.3
  • rubygem-actionpack-3_2 >= 3.2.12-1.13.1
  • rubygem-actionpack-3_2-doc >= 3.2.12-1.13.1
Patchnames:
openSUSE-2013-989
openSUSE-2014-1
openSUSE 13.1
  • rubygem-actionpack-3_2 >= 3.2.13-2.9.1
  • rubygem-actionpack-3_2-doc >= 3.2.13-2.9.1
Patchnames:
openSUSE-2013-990
openSUSE-2014-1