Vulnerability Description
RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. Upgrade to 3.1.3 or 2.2.2 (to be released).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rails Admin Project | Rails Admin | < 2.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/railsadminteam/rails_admin/commit/b5a287d82e2cbd1737a1a01e11ePatch
- https://github.com/railsadminteam/rails_admin/commit/d84b39884059c4ed50197cec852Patch
- https://github.com/railsadminteam/rails_admin/issues/3686Issue Tracking
- https://github.com/railsadminteam/rails_admin/security/advisories/GHSA-8qgm-g2vvVendor Advisory
- https://rubygems.org/gems/rails_admin/versions/2.3.0Patch
- https://rubygems.org/gems/rails_admin/versions/3.1.3Patch
- https://github.com/railsadminteam/rails_admin/commit/b5a287d82e2cbd1737a1a01e11ePatch
- https://github.com/railsadminteam/rails_admin/commit/d84b39884059c4ed50197cec852Patch
- https://github.com/railsadminteam/rails_admin/issues/3686Issue Tracking
- https://github.com/railsadminteam/rails_admin/security/advisories/GHSA-8qgm-g2vvVendor Advisory
- https://rubygems.org/gems/rails_admin/versions/2.3.0Patch
- https://rubygems.org/gems/rails_admin/versions/3.1.3Patch
FAQ
What is CVE-2024-39308?
CVE-2024-39308 is a vulnerability with a CVSS score of 5.4 (MEDIUM). RailsAdmin is a Rails engine that provides an interface for managing data. RailsAdmin list view has the XSS vulnerability, caused by improperly-escaped HTML title attribute. Upgrade to 3.1.3 or 2.2.2 ...
How severe is CVE-2024-39308?
CVE-2024-39308 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-39308?
Check the references section above for vendor advisories and patch information. Affected products include: Rails Admin Project Rails Admin.