RubySec

Providing security resources for the Ruby community

CVE-2012-6684 (redcloth): RedCloth Cross-site Scripting vulnerability

RedCloth Cross-site Scripting vulnerability

Published: October 24, 2017

SECURITY IDENTIFIERS

GEM

redcloth

SEVERITY

CVSS v2.0: 4.3 (Medium)

PATCHED VERSIONS

>= 4.3.0

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a "javascript:" URI.

RELATED