4 ms·
Three vulnerabilities announced at the same time... * [CVE-2013-1855] XSS vulnerability in sanitize_css in Action Pack [1] * [CVE-2013-1856] XML Parsing Vulne
by slashdotdash 14y ago
Three vulnerabilities announced at the same time...
* [CVE-2013-1855] XSS vulnerability in sanitize_css in Action Pack [1]
* [CVE-2013-1856] XML Parsing Vulnerability affecting JRuby users [2]
* [CVE-2013-1857] XSS Vulnerability in the `sanitize` helper of Ruby on Rails [3]
Two of these affect all Rails versions, not just JRuby, so are more serious.
[1] https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/4_QHo4BqnN8 https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...
[2] https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/KZwsQbYsOiI https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...
[3] https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/zAAU7vGTPvI https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...
- cheald 14y agoI was gonna post 'em all, but my second one got auto-dead'd. Probably tripped the spam filter.
- matthuggins 14y agoIs it possible to update the title of this post to remove the "affecting JRuby users" portion? The current title will give non-JRuby users a false sense of security.
- cheald 14y agoThis vulnerability is only applicable to JRuby users who use the JDOM parser. JDOM is not usable on non-JRuby platforms.
- matthuggins 14y agoCVE-2013-1855 & CVE-2013-1857 are applicable to ALL Ruby users, not just JRuby.
- cheald 14y agoOh, I read you now. Since the link goes to just the JRuby-related announcement, I'm going to leave it in place for now, but please go ahead and submit the other two (especially the sanitize() one) - the spam filter seems to be upset at me. :)
- tenderlove 14y agoThere's supposed to be 4, but google groups seems to be swallowing my announcement emails. :'( Here is the fourth one: https://groups.google.com/forum/#!topic/ruby-security-ann/o0Dsdk2WrQ0 https://groups.google.com/forum/#!topic/ruby-security-ann/o0...