CVE-2023-23913
unknown
CVSS v3
—
CVSS v2
—
VIR risk
—
Description
There is a potential DOM based cross-site scripting issue in rails-ujs which leverages the Clipboard API to target HTML elements that are assigned the contenteditable attribute. This has the potential to occur when pasting malicious HTML content from the clipboard that includes a data-method, data-remote or data-disable-with attribute.
Predictions
Exploit likelihood
30%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2023-23913
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2023-23913.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | | |
| debian | bookworm | fixed | 2:6.1.7.3+dfsg-1 |
| debian | bullseye | fixed | 2:6.0.3.7+dfsg-2+deb11u2 |
| debian | forky | fixed | 2:6.1.7.3+dfsg-1 |
| debian | sid | fixed | 2:6.1.7.3+dfsg-1 |
| debian | trixie | fixed | 2:6.1.7.3+dfsg-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| RubyGems | actionview | !< 5.1.0||<~> 6.1.7.3 | ~> 6.1.7.3 |
| RubyGems | actionview | >=5.1.0,<6.1.7.3 | 6.1.7.3 |
| RubyGems | actionview | >=7.0.0,<7.0.4.3 | 7.0.4.3 |
References
- https://discuss.rubyonrails.org/t/cve-2023-23913-dom-based-cross-site-scripting-in-rails-ujs-for-contenteditable-html-elements/82468
- https://www.suse.com/security/cve/CVE-2023-23913.html
- https://nvd.nist.gov/vuln/detail/CVE-2023-23913
- https://github.com/rails/rails/commit/5037a13614d71727af8a175063bcf6ba1a74bdbd
- https://github.com/rails/rails/commit/73009ea59a811b28e8ec2a9c9bc24635aa891214
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1033263
- https://github.com/rails/rails
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2023-23913.yml
- https://security.netapp.com/advisory/ntap-20240605-0007
- https://www.debian.org/security/2023/dsa-5389
- https://security-tracker.debian.org/tracker/CVE-2023-23913
Verify integrity in audit chain (admin only). AS-IS.