CVE-2020-15169

NameCVE-2020-15169
DescriptionIn Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of the `t` and `translate` helpers could be susceptible to XSS attacks. When an HTML-unsafe string is passed as the default for a missing translation key named html or ending in _html, the default string is incorrectly marked as HTML-safe and not escaped. This is patched in versions 6.0.3.3 and 5.2.4.4. A workaround without upgrading is proposed in the source advisory.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2403-1, DSA-4766-1
NVD severitymedium
Debian Bugs970040

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rails (PTS)stretch2:4.2.7.1-1+deb9u2vulnerable
stretch (security)2:4.2.7.1-1+deb9u4fixed
buster2:5.2.2.1+dfsg-1+deb10u1vulnerable
buster (security)2:5.2.2.1+dfsg-1+deb10u2fixed
bullseye, sid2:6.0.3.4+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
railssourcestretch2:4.2.7.1-1+deb9u4DLA-2403-1
railssourcebuster2:5.2.2.1+dfsg-1+deb10u2DSA-4766-1
railssource(unstable)2:6.0.3.3+dfsg-1970040

Notes

https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2020-15169.yml
https://groups.google.com/g/rubyonrails-security/c/b-C9kSGXYrc?pli=1
https://github.com/rails/rails/commit/e663f084460ea56c55c3dc76f78c7caeddeeb02e (master)
https://github.com/rails/rails/commit/aaa7ab1320330b3c4fa8f0fbda716dcfa21e3d65 (5.2)

Search for package or bug name: Reporting problems