Vulnerability Name:

CVE-2013-4492 (CCN-89434)

Assigned:2013-12-03
Published:2013-12-03
Updated:2023-02-13
Summary:i18n gem for Ruby is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by exceptions.rb. A remote attacker could exploit this vulnerability using MissingTranslation messages to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2013-4492

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RubyGems Web site
i18n gem for Ruby

Source: CCN
Type: SA55849
Ruby i18n Gem Cross-Site Scripting Vulnerability

Source: CCN
Type: SA56661
IBM Security Network Protection Ruby Two Vulnerabilities

Source: CCN
Type: Ruby On Rails Web site
Rails 3.2.16 and 4.0.2 have been released!

Source: secalert@redhat.com
Type: Patch, Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: DEBIAN
Type: DSA-2830
ruby-i18n -- cross-site scripting

Source: CCN
Type: BID-64076
RubyGems i18n Cross Site Scripting Vulnerability

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
i18n-ruby-cve20134492-xss(89434)

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Vulnerability Name:

CVE-2013-4492 (CCN-175650)

Assigned:2013-12-30
Published:2013-12-30
Updated:2013-12-30
Summary:Ruby I18N is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially crafted I18n::MissingTranslationData.new call to execute script to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.
CVSS v3 Severity:6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2013-4492

Source: XF
Type: UNKNOWN
rubyi18n-cve20134492-xss(175650)

Source: CCN
Type: Ruby I18N GIT Repository
i18n

Source: CCN
Type: Ruby I18N GIT Repository
The I18n::MissingTranslation exception escapes key names for its html

Source: CCN
Type: Ruby Web site
Rails 3.2.16 and 4.0.2 have been released!

Source: CCN
Type: Debian Web site
DSA-2830-1 ruby-i18n -- cross-site scripting

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:26186
P
Security update for libqt4 (Important)
2021-12-22
oval:org.opensuse.security:def:26110
P
Security update for aspell (Important)
2021-08-25
oval:org.opensuse.security:def:20134492
V
CVE-2013-4492
2021-08-15
oval:org.opensuse.security:def:36561
P
rubygem-i18n-0_6-0.6.0-0.8.1 on GA media (Moderate)
2021-06-08
oval:org.opensuse.security:def:26122
P
Security update for python-urllib3 (Moderate)
2021-02-03
oval:org.opensuse.security:def:26111
P
Security update for cups (Moderate)
2021-02-02
oval:org.opensuse.security:def:26639
P
star on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:27211
P
libpython2_6-1_0 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26789
P
ntp on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26777
P
log4net on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:27884
P
Security update for rubygem-i18n-0_6
2020-12-01
oval:org.opensuse.security:def:26842
P
xen on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:27012
P
perl-HTML-Parser on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26395
P
Security update for MozillaThunderbird (Important)
2020-12-01
oval:org.opensuse.security:def:26436
P
Security update for pdns-recursor (Moderate)
2020-12-01
oval:org.opensuse.security:def:27524
P
openCryptoki on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:27114
P
ed on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26536
P
dbus-1 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26511
P
Security update for icingaweb2 (Moderate)
2020-12-01
oval:org.opensuse.security:def:27167
P
lcms on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26740
P
libarchive2 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26720
P
java-1_4_2-ibm on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:27849
P
Security update for openssl (Moderate)
2020-12-01
oval:org.opensuse.security:def:26828
P
system-config-printer on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26861
P
ant on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26314
P
Security update for iperf (Moderate)
2020-12-01
oval:org.opensuse.security:def:26435
P
Security update for znc (Low)
2020-12-01
oval:org.opensuse.security:def:26886
P
ecryptfs-utils-32bit on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:27065
P
yast2-core on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26452
P
Security update for phpMyAdmin (Moderate)
2020-12-01
oval:org.opensuse.security:def:26447
P
Security update for pdns (Important)
2020-12-01
oval:org.opensuse.security:def:27559
P
rubygem-i18n-0_6 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:27153
P
jpeg on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:26687
P
e2fsprogs on GA media (Moderate)
2020-12-01
oval:org.mitre.oval:def:21397
P
DSA-2830-1 ruby-i18n - cross-site scripting
2014-06-23
oval:com.ubuntu.disco:def:201344920000000
V
CVE-2013-4492 on Ubuntu 19.04 (disco) - medium.
2013-12-07
oval:com.ubuntu.bionic:def:201344920000000
V
CVE-2013-4492 on Ubuntu 18.04 LTS (bionic) - medium.
2013-12-07
oval:com.ubuntu.xenial:def:201344920000000
V
CVE-2013-4492 on Ubuntu 16.04 LTS (xenial) - medium.
2013-12-07
oval:com.ubuntu.artful:def:20134492000
V
CVE-2013-4492 on Ubuntu 17.10 (artful) - medium.
2013-12-06
oval:com.ubuntu.trusty:def:20134492000
V
CVE-2013-4492 on Ubuntu 14.04 LTS (trusty) - medium.
2013-12-06
oval:com.ubuntu.cosmic:def:201344920000000
V
CVE-2013-4492 on Ubuntu 18.10 (cosmic) - medium.
2013-12-06
oval:com.ubuntu.bionic:def:20134492000
V
CVE-2013-4492 on Ubuntu 18.04 LTS (bionic) - medium.
2013-12-06
oval:com.ubuntu.xenial:def:20134492000
V
CVE-2013-4492 on Ubuntu 16.04 LTS (xenial) - medium.
2013-12-06
oval:com.ubuntu.cosmic:def:20134492000
V
CVE-2013-4492 on Ubuntu 18.10 (cosmic) - medium.
2013-12-06
oval:com.ubuntu.precise:def:20134492000
V
CVE-2013-4492 on Ubuntu 12.04 LTS (precise) - medium.
2013-12-06
BACK