CVE-2022-27777
MEDIUM6.1EPSS 1.4%XSS Vulnerability in Action View tag helpers
Published: 4/27/2022Modified: 4/28/2026
Description
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
Affected packages (2)
- Debian/railsfrom 0, < 2:6.0.3.7+dfsg-2+deb11u1
- RubyGems/actionviewfrom 0, < 5.2.7.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
References (10)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2022-27777
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2022-27777
- PATCHhttps://github.com/rails/rails
- WEBhttps://discuss.rubyonrails.org/t/cve-2022-27777-possible-xss-vulnerability-in-action-view-tag-helpers/80534
- WEBhttps://github.com/rails/rails/commit/649516ce0feb699ae06a8c5e81df75d460cc9a85
- WEBhttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2022-27777.yml
- WEBhttps://groups.google.com/g/ruby-security-ann/c/9wJPEDv-iRw
- WEBhttps://lists.debian.org/debian-lts-announce/2022/09/msg00002.html
- WEBhttps://rubyonrails.org/2022/4/26/Rails-7-0-2-4-6-1-5-1-6-0-4-8-and-5-2-7-1-have-been-released
- WEBhttps://www.debian.org/security/2023/dsa-5372