CVE-2014-0046

low
Published 2014-02-07 · Modified 2025-08-11
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

ember-source Cross-site Scripting vulnerability

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/56965

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://emberjs.com/blog/2014/02/07/ember-security-releases.html

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsember-source!< 1.2.0||<~> 1.2.2~> 1.2.2
ruby RubyGemsember-source>=1.2.0,<1.2.21.2.2
ruby RubyGemsember-source>=1.3.0,<1.3.21.3.2
ruby RubyGemsember-source>=1.4.0.beta.1,<1.4.0.beta.61.4.0.beta.6

Application impact

VendorProductVersionsFixed
emberjsember.js1.2.0
emberjsember.js1.2.1
emberjsember.js1.3.0
emberjsember.js1.3.1
emberjsember.js1.4.0

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.