CVE-2010-1330
JRuby <1.4.1 - XSS
Title source: llmDescription
The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.
Scores
EPSS
0.0043
EPSS Percentile
61.9%
Details
CWE
CWE-79
Status
published
Products (37)
jruby/jruby
< 1.4.0
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
... and 27 more
Published
Nov 23, 2012
Tracked Since
Feb 18, 2026