Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5389-1 | rails security update |
Github GHSA |
GHSA-pj73-v5mw-pm9j | Possible XSS Security Vulnerability in SafeBuffer#bytesplice |
Thu, 09 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
ssvc
|
Thu, 09 Jan 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross-Site-Scripting vulnerability was found in rubygem ActiveSupport. If the new bytesplice method is called on a SafeBuffer with untrusted user input, malicious code could be executed. | There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input. |
| References |
|
|
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2025-01-09T21:46:38.220Z
Reserved: 2023-03-10T19:36:27.051Z
Link: CVE-2023-28120
Updated: 2025-01-09T21:46:31.379Z
Status : Deferred
Published: 2025-01-09T01:15:07.637
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-28120
OpenCVE Enrichment
No data.
Debian DSA
Github GHSA