CVE-2010-1330

JRuby <1.4.1 - XSS

Title source: llm

Description

The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.

Scores

EPSS 0.0043
EPSS Percentile 61.9%

Details

CWE
CWE-79
Status published
Products (37)
jruby/jruby < 1.4.0
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
jruby/jruby
... and 27 more
Published Nov 23, 2012
Tracked Since Feb 18, 2026