CVE-2022-3704

NameCVE-2022-3704
DescriptionA vulnerability classified as problematic has been found in Ruby on Rails. This affects an unknown part of the file actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The name of the patch is be177e4566747b73ff63fd5f529fab564e475ed4. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-212319.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs1024274

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rails (PTS)buster2:5.2.2.1+dfsg-1+deb10u3vulnerable
buster (security)2:5.2.2.1+dfsg-1+deb10u5vulnerable
bullseye2:6.0.3.7+dfsg-2vulnerable
bookworm, sid2:6.1.7+dfsg-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
railssource(unstable)(unfixed)1024274

Notes

https://github.com/rails/rails/commit/be177e4566747b73ff63fd5f529fab564e475ed4
https://github.com/rails/rails/issues/46244

Search for package or bug name: Reporting problems