CVE-2013-0256: Canonical Ubuntu Linux

Medium severity, CVSS 4.3. EPSS: 3% chance of exploitation in the next 30 days.

darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 12.10 only
  • Ruby-Lang Rdoc: from 2.3.0, before 3.12 (fixed in 3.12); version 4.0.0 only
  • Ruby-Lang Ruby: version 1.9 only; version 1.9.1 only; version 1.9.2 only; version 1.9.3 only; version 2.0 only; version 2.0.0 only

Published 2013-03-01. Last modified 2026-06-16.