CVE-2014-0081: Opensuse

Medium severity, CVSS 4.3. EPSS: 4% chance of exploitation in the next 30 days.

Multiple cross-site scripting (XSS) vulnerabilities in actionview/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.17, 4.0.x before 4.0.3, and 4.1.x before 4.1.0.beta2 allow remote attackers to inject arbitrary web script or HTML via the (1) format, (2) negative_format, or (3) units parameter to the (a) number_to_currency, (b) number_to_percentage, or (c) number_to_human helper.

Affected products

  • Opensuse Opensuse: version 13.1 only
  • Opensuse Project Opensuse: version 12.3 only
  • Red Hat Cloudforms: version 3.0 only
  • Red Hat Enterprise Linux: version 6.0 only
  • Rubyonrails Rails: version 0.9.1 only; version 0.9.2 only; version 0.9.3 only; version 0.9.4 only; version 0.9.4.1 only; version 0.10.0 only; …
  • Rubyonrails Ruby On Rails: up to and including 3.2.16; version 0.5.0 only; version 0.5.5 only; version 0.5.6 only; version 0.5.7 only; version 0.6.0 only; …

Published 2014-02-20. Last modified 2026-06-17.