Improper Neutralization The advisory has been revoked - it doesn't affect any version of package actionpack  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of concept
EPSS
0.06% (26th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUBY-ACTIONPACK-3086619
  • published27 Oct 2022
  • disclosed27 Oct 2022
  • creditFreakyclown

Introduced: 27 Oct 2022

CVE-2022-3704  (opens in a new tab)
CWE-707  (opens in a new tab)

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Improper Neutralization via the setupMatchPaths function in the actionpack/lib/action_dispatch/middleware/templates/routes/_table.html.erb file. Exploiting this vulnerability might lead to Cross Site Scripting.

PoC

<svg><animate onend=alert(document.domain) attributeName=x dur=1s>

NOTE: The maintainers of this project consider it not a vulnerability since "This routing error page is only visible to developers, only in development mode, and only on localhost (or other domains configured to be 'local')."