CVE-2015-3226 is a cross-site scripting (XSS) vulnerability in the json/encoding.rb component of Active Support in Ruby on Rails versions 3.x, 4.1.x before 4.1.11, and 4.2.x before 4.2.2. This flaw allows remote attackers to inject arbitrary web script or HTML by crafting a malicious Hash that is improperly handled during JSON encoding. The vulnerability has a CVSS score of 4.3, indicating a medium attack complexity and a potential impact of partial integrity compromise, but no confidentiality or availability impact. While there are no known public exploits or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:3.0.0:*:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:3.1.0:*:*:*:*:*:*:* | ||
3.2.0CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:3.2.0:*:*:*:*:*:*:* | ||
3.2.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:3.2.1:*:*:*:*:*:*:* | ||
3.2.2CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:3.2.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.