Technical Advisory: Ruby on Rails – Possible XSS Vulnerability in ActionView tag helpers (CVE-2022-27777)
ID: b31b7f13-db1d-5e77-a51a-b526af225bdf
STIX ID: report--b31b7f13-db1d-5e77-a51a-b526af225bdf
Feed Name: NCC Research
Threat Score
This advisory (CVE-2022-27777) describes multiple reflected and potential stored XSS vulnerabilities in Ruby on Rails tag and form helpers that allow attacker-controlled attribute names or tag names to inject arbitrary JavaScript; affected Rails versions are prior to 7.0.2.4, 6.1.5.1, 6.0.4.8, and 5.2.7.1, and fixes/patches and upgraded releases are provided by the vendor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
