CVE-2022-27777
Published on: Not Yet Published
Last Modified on: 06/07/2022 02:35:00 PM UTC
Certain versions of Actionpack from Rubyonrails contain the following vulnerability:
A XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker to inject content if able to control input into specific attributes.
- CVE-2022-27777 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
[CVE-2022-27777] Possible XSS Vulnerability in Action View tag helpers - Security Announcements - Ruby on Rails Discussions | discuss.rubyonrails.org text/html |
![]() |
Related QID Numbers
- 690858 Free Berkeley Software Distribution (FreeBSD) Security Update for rails (9db93f3d-c725-11ec-9618-000d3ac47524)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Rubyonrails | Actionpack | All | All | All | All |
- cpe:2.3:a:rubyonrails:actionpack:*:*:*:*:*:ruby:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
RubySec ➜ CVE-2022-27777 (actionview): Possible XSS Vulnerability in Action View tag helpers rubysec.com/advisories/CVE… | 2022-04-27 08:20:35 |
![]() |
Technical Advisory: Ruby on Rails – Possible XSS Vulnerability in ActionView tag helpers (CVE-2022-27777), by Álvar… twitter.com/i/web/status/1… | 2022-05-06 17:56:56 |
![]() |
Ruby on Rails – Possible #XSS Vulnerability in ActionView tag helpers CVE-2022-27777 #CyberSecurity #rubyonrails #infosec #CVE | 2022-05-07 04:23:51 |
![]() |
“Technical Advisory: Ruby on Rails – Possible XSS Vulnerability in ActionView tag helpers (CVE-2022-27777)” (1 user) htn.to/Lq4DstdK21 | 2022-05-07 14:53:49 |
![]() |
Technical Advisory: Ruby on Rails – Possible XSS Vulnerability in ActionView tag helpers (CVE-2022-27777) – NCC Gro… twitter.com/i/web/status/1… | 2022-05-08 13:24:00 |
![]() |
Technical Advisory: Ruby on Rails – Possible XSS Vulnerability in ActionView tag helpers (CVE-2022-27777) research.nccgroup.com/2022/05/06/tec… | 2022-05-09 14:07:46 |
![]() |
New Blog: Technical Advisory: Ruby on Rails – Possible XSS Vulnerability in ActionView tag helpers (CVE-2022-27777) research.nccgroup.com/2022/05/06/tec… | 2022-05-09 17:05:02 |
![]() |
CVE-2022-27777 : A #XSS Vulnerability in Action View tag helpers >= 5.2.0 and < 5.2.0 which would allow an attacker… twitter.com/i/web/status/1… | 2022-05-26 17:06:24 |
![]() |
Technical Advisory: Ruby on Rails – Possible XSS Vulnerability in ActionView tag helpers (CVE-2022-27777) | 2022-05-07 06:37:06 |
![]() |
CVE-2022-27777 | 2022-05-26 18:38:54 |