Description
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, `SafeBuffer#%` does not propagate the `@html_unsafe` flag to the newly created buffer. If a `SafeBuffer` is mutated in place (e.g. via `gsub!`) and then formatted with `%` using untrusted arguments, the result incorrectly reports `html_safe? == true`, bypassing ERB auto-escaping and possibly leading to XSS. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.
Remediation
References
Related Vulnerabilities
WordPress Plugin BestSmallShopLite Cross-Site Scripting (1.0.1)
Joomla! Core 3.x.x Cross-Site Scripting (3.0.0 - 3.9.15)
MediaWiki CVE-2023-22909 Vulnerability (CVE-2023-22909)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.4.37.727)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall SQL Injection (3.9.0)