Vulnerability Name:

CVE-2014-2538 (CCN-91956)

Assigned:2014-03-19
Published:2014-03-19
Updated:2015-10-08
Summary:Cross-site scripting (XSS) vulnerability in lib/rack/ssl.rb in the rack-ssl gem before 1.4.0 for Ruby allows remote attackers to inject arbitrary web script or HTML via a URI, which might not be properly handled by third-party adapters such as JRuby-Rack.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:H/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2014-2538

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2014:0515

Source: CCN
Type: oss-security Mailing List, Wed 19 Mar 2014
CVE Request: rack-ssl rubygem: XSS in error page

Source: CCN
Type: SA57466
Ruby rack-ssl Gem Error Page Cross-Site Scripting Vulnerability

Source: SECUNIA
Type: Vendor Advisory
57466

Source: MLIST
Type: UNKNOWN
[oss-security] 20140319 Re: CVE Request: rack-ssl rubygem: XSS in error page

Source: BID
Type: UNKNOWN
66314

Source: CCN
Type: BID-66314
RubyGems rack-ssl 'lib/rack/ssl.rb' Cross Site Scripting Vulnerability

Source: XF
Type: UNKNOWN
rackssl-cve20142538-xss(91956)

Source: CONFIRM
Type: Patch
https://github.com/josh/rack-ssl/commit/9d7d7300b907e496db68d89d07fbc2e0df0b487b

Source: CCN
Type: RubyGems Web site
rack-ssl gem for Ruby

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-2538

Vulnerable Configuration:Configuration 1:
  • cpe:/a:joshua_peek:rack-ssl:1.0.0:*:*:*:*:ruby:*:*
  • OR cpe:/a:joshua_peek:rack-ssl:1.1.0:*:*:*:*:ruby:*:*
  • OR cpe:/a:joshua_peek:rack-ssl:1.2.0:*:*:*:*:ruby:*:*
  • OR cpe:/a:joshua_peek:rack-ssl:1.3.0:*:*:*:*:ruby:*:*
  • OR cpe:/a:joshua_peek:rack-ssl:1.3.1:*:*:*:*:ruby:*:*
  • OR cpe:/a:joshua_peek:rack-ssl:1.3.2:*:*:*:*:ruby:*:*
  • OR cpe:/a:joshua_peek:rack-ssl:1.3.3:*:*:*:*:ruby:*:*
  • OR cpe:/a:joshua_peek:rack-ssl:*:*:*:*:*:ruby:*:* (Version <= 1.3.4)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:26125
    P
    Security update for grilo (Important)
    2021-09-09
    oval:org.opensuse.security:def:26114
    P
    Security update for openexr (Important)
    2021-09-02
    oval:org.opensuse.security:def:26113
    P
    Security update for mysql-connector-java (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:20142538
    V
    CVE-2014-2538
    2021-08-15
    oval:org.opensuse.security:def:36564
    P
    rubygem-rack-ssl-1.3.2-0.12.5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26189
    P
    Security update for subversion (Important)
    2021-02-10
    oval:org.opensuse.security:def:26724
    P
    kdebase3-runtime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27853
    P
    Security update for php53 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26831
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26865
    P
    apache2-mod_php53 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26317
    P
    Security update for chromium (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26439
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:26889
    P
    enscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27069
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26455
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:26451
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:27562
    P
    rubygem-rack-ssl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27157
    P
    kdebase4-runtime on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26690
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26643
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27215
    P
    libsndfile on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26792
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26781
    P
    mailman on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27888
    P
    Security update for rubygem-rack-ssl
    2020-12-01
    oval:org.opensuse.security:def:26845
    P
    xorg-x11-libs-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27016
    P
    postgresql on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26398
    P
    Security update for pdns-recursor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26440
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:27527
    P
    openslp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27118
    P
    evince on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26539
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26515
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27171
    P
    libQtWebKit4-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26743
    P
    libdrm on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201425380000000
    V
    CVE-2014-2538 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-03-25
    oval:com.ubuntu.artful:def:20142538000
    V
    CVE-2014-2538 on Ubuntu 17.10 (artful) - medium.
    2014-03-25
    oval:com.ubuntu.xenial:def:20142538000
    V
    CVE-2014-2538 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-03-25
    oval:com.ubuntu.xenial:def:201425380000000
    V
    CVE-2014-2538 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-03-25
    oval:com.ubuntu.bionic:def:20142538000
    V
    CVE-2014-2538 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-03-25
    oval:com.ubuntu.disco:def:201425380000000
    V
    CVE-2014-2538 on Ubuntu 19.04 (disco) - medium.
    2014-03-25
    oval:com.ubuntu.cosmic:def:20142538000
    V
    CVE-2014-2538 on Ubuntu 18.10 (cosmic) - medium.
    2014-03-25
    oval:com.ubuntu.cosmic:def:201425380000000
    V
    CVE-2014-2538 on Ubuntu 18.10 (cosmic) - medium.
    2014-03-25
    oval:com.ubuntu.trusty:def:20142538000
    V
    CVE-2014-2538 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-03-25
    BACK
    joshua_peek rack-ssl 1.0.0
    joshua_peek rack-ssl 1.1.0
    joshua_peek rack-ssl 1.2.0
    joshua_peek rack-ssl 1.3.0
    joshua_peek rack-ssl 1.3.1
    joshua_peek rack-ssl 1.3.2
    joshua_peek rack-ssl 1.3.3
    joshua_peek rack-ssl *