bugs.debian.org
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1033263 CVE-2023-23913
MEDIUM
rails-ujs vulnerable to DOM Based Cross-site Scripting contenteditable HTML Elements
Record summary
CVE-2023-23913 has a selected CVSS score of 6.3 (medium).
Description
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 9, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
rails-ujsBrowse Rails / rails-ujs | CVE List | 6.1.7.3 to < 6.1.7.3 | affected |
| 7.0.4.3 to < 7.0.4.3 | affected | ||
| 5.1.0 to < 5.1.0 | unaffected | ||
actionviewBrowse RubyGems / actionview | GitHub Advisory | 5.1.0 to < 6.1.7.3 · Fixed in 6.1.7.3 | affected |
| 7.0.0 to < 7.0.4.3 · Fixed in 7.0.4.3 | affected |
References
9discuss.rubyonrails.org
https://discuss.rubyonrails.org/t/cve-2023-23913-dom-based-cross-site-scripting-in-rails-ujs-for-contenteditable-html-elements/82468 github.com
https://github.com/rails/rails github.com
https://github.com/rails/rails/commit/5037a13614d71727af8a175063bcf6ba1a74bdbd github.com
https://github.com/rails/rails/commit/73009ea59a811b28e8ec2a9c9bc24635aa891214 github.com
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2023-23913.yml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-23913 security.netapp.com
https://security.netapp.com/advisory/ntap-20240605-0007 debian.org
https://www.debian.org/security/2023/dsa-5389