PT-2023-19296 · Ruby On Rails+2 · Rails-Ujs+2

·

CVE-2023-23913

·

Publicado

2023-03-22

·

Atualizado

2025-01-09

CVSS v3.1

6.3

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions rails-ujs versions 5.1.0 through 6.1.7.2 rails-ujs versions 5.1.0 through 7.0.4.2
Description There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote, or data-disable-with attribute. If the specified malicious HTML clipboard content is provided to a contenteditable element, this could result in the arbitrary execution of javascript on the origin in question.
Recommendations For versions 5.1.0 through 6.1.7.2, upgrade to version 6.1.7.3. For versions 5.1.0 through 7.0.4.2, upgrade to version 7.0.4.3. As a temporary workaround, consider removing the contenteditable attribute from elements in pages that rails-ujs will interact with. Apply the provided patches for the 6.1 series (rails-ujs-data-method-contenteditable-6-1.patch) or the 7.0 series (rails-ujs-data-method-contenteditable-7-0.patch) to aid in mitigation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2024-7877
CVE-2023-23913
DSA-5389-1
GHSA-XP5H-F8JF-RC8Q
OESA-2024-1774
OESA-2024-1775
OESA-2024-1776
OPENSUSE-SU-2023_3813-1
SUSE-SU-2023:3813-1
SUSE-SU-2023_3813-1

Produtos afetados

Alt Linux
Suse
Rails-Ujs