Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-0081

15
FAUCET Score

CVE-2014-0081 describes multiple cross-site scripting (XSS) vulnerabilities in Ruby on Rails versions before 3.2.17, 4.0.3, and 4.1.0.beta2, specifically within the number formatting helpers (number_to_currency, number_to_percentage, number_to_human). Attackers can inject arbitrary web script or HTML by manipulating the format, negative_format, or units parameters. This vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and potential for partial integrity impact, as it requires user interaction (AV:N/AC:M/Au:N/C:N/I:P/A:N). There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog. Despite limited community discussion and media coverage, the vulnerability was publicly disclosed and documented.

Impacted Technologies

VendorProductVersion(s)CPE
0.9.1CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:0.9.1:*:*:*:*:*:*:*
0.9.2CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:0.9.2:*:*:*:*:*:*:*
0.9.3CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:0.9.3:*:*:*:*:*:*:*
0.9.4CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:0.9.4:*:*:*:*:*:*:*
0.9.4.1CPE matchmatch criteria
cpe:2.3:a:rubyonrails:rails:0.9.4.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.03%
Probability of exploitation in next 30 days
EPSS Percentile
89.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0403 is in the 86th percentile among its peer group of 19,958 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-rubygem-linux_admin-0:0.7.0-1.el6cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-rubygem-more_core_extensions-0:1.1.2-1.el6cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-rubygem-nokogiri-0:1.5.6-3.el6cf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for RHEL-6Fixed in: ruby193-rubygem-actionpack-1:3.2.8-5.3.el6
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: cfme-0:5.2.2.3-1.el6cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-ruby-0:1.9.3.448-40.1.el6
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-rubygem-actionpack-1:3.2.13-5.el6cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-rubygem-amq-protocol-0:1.9.2-3.el6cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-rubygem-bunny-0:1.0.7-1.el6cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-rubygem-excon-0:0.31.0-1.el6cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.xFixed in: ruby193-rubygem-fog-0:1.19.0-1.el6cf
View patch
rubygemspatch availablevia ghsa
Product: railsFixed in: 3.2.17
rubygemspatch availablevia ghsa
Product: railsFixed in: 4.0.3
rubygemspatch availablevia ghsa
Product: actionpackFixed in: 3.2.17
rubygemspatch availablevia ghsa
Product: actionpackFixed in: 4.0.3
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 3Fixed in: ruby193-rubygem-actionpack
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 4Fixed in: ruby193-rubygem-actionpack
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: ruby193-rubygem-actionpack
redhatno patchvia redhat_api
Product: Red Hat Software CollectionsFixed in: ror40-rubygem-actionpack
redhatend of lifevia redhat_api
Product: OpenShift Enterprise 1Fixed in: ruby193-rubygem-actionpack
redhatend of lifevia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: ruby193-rubygem-actionpack

Vendor Advisories (2)

rubygemsGHSA-m46p-ggm5-5j83medium

Rails vulnerable to Cross-site Scripting

Oct 24, 2017
redhatCVE-2014-0081Moderate

rubygem-actionpack: number_to_currency, number_to_percentage and number_to_human XSS vulnerability

Feb 18, 2014

References

lists.opensuse.org / opensuse-updates/2014-02/msg00081.html
Third Party Advisory
openwall.com / lists/oss-security/2014/02/18/8
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-0215.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-0306.html
Third Party Advisory
secunia.com / advisories/57376
Permissions Required
groups.google.com / forum/message/raw
Third Party Advisory
securityfocus.com / bid/65647
Third Party AdvisoryVDB Entry
securitytracker.com / id/1029782
Third Party AdvisoryVDB Entry