OESA-2021-1180

    Dashboard / Vulnerabilities / OESA-2021-1180

    OESA-2021-1180

    Published: 15 May 2021Last Modified: 18 Aug 2026
    Upstream:

    Summary: rubygem-actionview security update

    Details: Simple, battle-tested conventions and helpers for building web pages. Security Fix(es): In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View s translation helpers. Views that allow the user to control the default (not found) value of the t and translate helpers could be susceptible to XSS attacks. When an HTML-unsafe string is passed as the default for a missing translation key named html or ending in _html, the default string is incorrectly marked as HTML-safe and not escaped. This is patched in versions 6.0.3.3 and 5.2.4.4. A workaround without upgrading is proposed in the source advisory.(CVE-2020-15169)

    Affected packages

    Package

    Name: rubygem-actionview

    Purl: pkg:rpm/openEuler/rubygem-actionview&distro=openEuler-20.03-LTS-SP1

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -5.2.4.4-1.oe1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2021-1180 | CVE-DB