4.3

CVE-2010-1330

Exploit
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jruby ≫ Jruby Version <= 1.4.0
Jruby ≫ Jruby Version 0.9.0
Jruby ≫ Jruby Version 0.9.1
Jruby ≫ Jruby Version 0.9.2
Jruby ≫ Jruby Version 0.9.8
Jruby ≫ Jruby Version 0.9.9
Jruby ≫ Jruby Version 1.0.0
Jruby ≫ Jruby Version 1.0.0 Update rc1
Jruby ≫ Jruby Version 1.0.0 Update rc2
Jruby ≫ Jruby Version 1.0.0 Update rc3
Jruby ≫ Jruby Version 1.0.1
Jruby ≫ Jruby Version 1.0.2
Jruby ≫ Jruby Version 1.0.3
Jruby ≫ Jruby Version 1.1
Jruby ≫ Jruby Version 1.1 Update beta1
Jruby ≫ Jruby Version 1.1 Update rc1
Jruby ≫ Jruby Version 1.1 Update rc2
Jruby ≫ Jruby Version 1.1 Update rc3
Jruby ≫ Jruby Version 1.1.1
Jruby ≫ Jruby Version 1.1.2
Jruby ≫ Jruby Version 1.1.3
Jruby ≫ Jruby Version 1.1.4
Jruby ≫ Jruby Version 1.1.5
Jruby ≫ Jruby Version 1.1.6
Jruby ≫ Jruby Version 1.1.6 Update rc1
Jruby ≫ Jruby Version 1.2.0
Jruby ≫ Jruby Version 1.2.0 Update rc1
Jruby ≫ Jruby Version 1.2.0 Update rc2
Jruby ≫ Jruby Version 1.3.0
Jruby ≫ Jruby Version 1.3.0 Update rc1
Jruby ≫ Jruby Version 1.3.0 Update rc2
Jruby ≫ Jruby Version 1.3.1
Jruby ≫ Jruby Version 1.4.0 Update rc1
Jruby ≫ Jruby Version 1.4.0 Update rc2
Jruby ≫ Jruby Version 1.4.0 Update rc3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.22% 0.803
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://rhn.redhat.com/errata/RHSA-2011-1456.html
http://secunia.com/advisories/46891
Vendor Advisory
http://www.jruby.org/2010/04/26/jruby-1-4-1-xss-vulnerability.html
Patch
Vendor Advisory
Exploit
http://www.osvdb.org/77297
https://bugs.gentoo.org/show_bug.cgi?id=317435
https://bugzilla.redhat.com/show_bug.cgi?id=750306
https://exchange.xforce.ibmcloud.com/vulnerabilities/80277