CVE-2013-1855

Source
https://cve.org/CVERecord?id=CVE-2013-1855
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2013-1855.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2013-1855
Aliases
Downstream
Withdrawn
2026-01-27T04:12:06.686199Z
Published
2013-03-19T22:55:01Z
Modified
2026-01-27T04:12:06.686199Z
Summary
[none]
Details

The sanitizecss method in lib/actioncontroller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.

References

Affected packages