CVE-2018-16471
Summary
| CVE | CVE-2018-16471 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-13 23:29:00 UTC |
| Updated | 2023-11-07 02:53:00 UTC |
| Description | There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Rack Project | Rack | All | All | All | All |
| Application | Rack Project | Rack | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [security-announce] openSUSE-SU-2020:0214-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Google Groups | MISC | groups.google.com | Mailing List, Patch, Third Party Advisory |
| USN-4089-1: Rack vulnerability | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| [security-announce] openSUSE-SU-2019:1553-1: moderate: Security update f | SUSE | lists.opensuse.org | |
| Google Groups | groups.google.com | ||
| [SECURITY] [DLA 1585-1] ruby-rack security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.