Release date:
Updated on:
Affected Systems:
Ruby on Rails 3.x
Ruby on Rails 2.x
Ruby on Rails 1.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54959
Cve id: CVE-2012-3463
Ruby on Rails (RoR or Rails) is an open-source Web application framework written in Ruby. It is developed in strict accordance with the MVC structure.
Ruby on Rails 3.0.17 3. there is an XSS vulnerability in actionpack/lib/action_view/helpers/form_tag_helper.rb of Version x, version 3.1.x earlier than Version 3.1.8, and version 3.2.8 earlier, remote attackers can inject arbitrary Web scripts or HTML to the select_tag Helper Program through the prompt field.
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby on Rails
-------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.rubyonrails.com/