CVE-2007-3227
Moderate severity vulnerability that affects rails
EPSS 13.9%
描述
Cross-site scripting (XSS) vulnerability in the to_json (ActiveRecord::Base#to_json) function in Ruby on Rails before edge 9606 allows remote attackers to inject arbitrary web script via the input values.
如何修補 CVE-2007-3227
要修補 CVE-2007-3227,請將受影響套件升級到下列已修補版本。
- Debian/rails—升級至 1.2.5-1 或更新版本
- RubyGems/rails—升級至 1.2.5 或更新版本
CVE-2007-3227 正在被利用嗎?
中等 — EPSS 為 13.9%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 1.2.5-1
- from 0, < 1.2.5