CVE-2013-1857: Red Hat Enterprise Linux

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.

Affected products

  • Red Hat Enterprise Linux: version 6.0 only
  • Rubyonrails Rails: version 0.9.1 only; version 0.9.2 only; version 0.9.3 only; version 0.9.4 only; version 0.9.4.1 only; version 0.10.0 only; …
  • Rubyonrails Ruby On Rails: up to and including 2.3.17; version 0.5.0 only; version 0.5.5 only; version 0.5.6 only; version 0.5.7 only; version 0.6.0 only; …

Published 2013-03-19. Last modified 2026-06-16.