CVE-2009-3009
Summary
| CVE | CVE-2009-3009 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-09-08 18:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rubyonrails | Rails | 2.0.0 | All | All | All |
| Application | Rubyonrails | Rails | 2.0.0 | rc1 | All | All |
| Application | Rubyonrails | Rails | 2.0.0 | rc2 | All | All |
| Application | Rubyonrails | Rails | 2.0.1 | All | All | All |
| Application | Rubyonrails | Rails | 2.0.2 | All | All | All |
| Application | Rubyonrails | Rails | 2.0.4 | All | All | All |
| Application | Rubyonrails | Rails | 2.1.0 | All | All | All |
| Application | Rubyonrails | Rails | 2.1.1 | All | All | All |
| Application | Rubyonrails | Rails | 2.1.2 | All | All | All |
| Application | Rubyonrails | Rails | 2.2.0 | All | All | All |
| Application | Rubyonrails | Rails | 2.2.1 | All | All | All |
| Application | Rubyonrails | Rails | 2.2.2 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.2 | All | All | All |
| Application | Rubyonrails | Rails | 2.3.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:017 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| #545063 - Security fixes (incl. CVE-2009-3009) - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-1887-1 rails | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| Ruby on Rails Form Helpers Unicode String Handling Cross Site Scripting Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| XSS Vulnerability in Ruby on Rails - Ruby on Rails: Security | Google Groups | af854a3a-2127-422b-91ae-364da2661108 | groups.google.com | Patch |
| www.osvdb.org/57666 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| APPLE-SA-2010-03-29-1 Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Ruby on Rails Unicode Input Cross-Site Scripting Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Ruby on Rails Input Validation Flaw in Form Helpers Permits Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| Debian update for rails - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| About the security content of Security Update 2010-002 / Mac OS X v10.6.3 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Riding Rails: XSS Vulnerability in Ruby on Rails | af854a3a-2127-422b-91ae-364da2661108 | weblog.rubyonrails.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.