Skip to content

[GHSA-vxvp-4xwc-jpp6] activesupport Cross-site Scripting vulnerability#6383

Merged
advisory-database[bot] merged 1 commit intotjuyuxinzhang/advisory-improvement-6383from
tjuyuxinzhang-GHSA-vxvp-4xwc-jpp6
Nov 4, 2025
Merged

[GHSA-vxvp-4xwc-jpp6] activesupport Cross-site Scripting vulnerability#6383
advisory-database[bot] merged 1 commit intotjuyuxinzhang/advisory-improvement-6383from
tjuyuxinzhang-GHSA-vxvp-4xwc-jpp6

Conversation

@tjuyuxinzhang
Copy link

Updates

  • Affected products
  • Description
  • References

Comments
The current advisory incorrectly implies that Rails 3.x series are affected.
Per official clarification from the Rails core team, Rails 3.2.22 and earlier 3.2.x versions are not vulnerable, as the affected code path does not exist in those releases.
This correction aligns with upstream patches and confirmed tests.

References for this correction:
Core Developer Retraction
https://groups.google.com/forum/#!searchin/rubyonrails-core/CVE-2015-3226/rubyonrails-core/qBUqVlXERag/kuH3wQk1kxUJ
→ Clarifies that Rails 3.2.22 (and earlier 3.2.x) are not affected, as the vulnerable code path does not exist in those versions.

GitHub Advisory Database
GHSA-vxvp-4xwc-jpp6
→ Lists the correct affected component (activesupport) and version range (4.1.0–4.1.10, 4.2.0–4.2.1).

@github-actions github-actions bot changed the base branch from main to tjuyuxinzhang/advisory-improvement-6383 November 4, 2025 18:59
@advisory-database advisory-database bot merged commit f985c14 into tjuyuxinzhang/advisory-improvement-6383 Nov 4, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @tjuyuxinzhang! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the tjuyuxinzhang-GHSA-vxvp-4xwc-jpp6 branch November 4, 2025 20:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant