{"id":"CVE-2009-3009","aliases":["GHSA-8qrh-h9m2-5fvf"],"url":"https://o3.security/vulnerability/CVE-2009-3009","summary":"Cross site scripting that affects rails","details":"Cross-site scripting (XSS) vulnerability in Ruby on Rails 2.x before 2.2.3, and 2.3.x before 2.3.4, allows remote attackers to inject arbitrary web script or HTML by placing malformed Unicode strings into a form helper.","published":"2009-09-08T18:30:00Z","modified":"2026-04-10T03:40:52.629215Z","cvss":null,"epss":{"score":0.03022,"percentile":0.86649,"asOf":"2026-09-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"actionpack","fixedVersion":"2.2.3"},{"ecosystem":"RubyGems","name":"actionpack","fixedVersion":"2.3.4"},{"ecosystem":"RubyGems","name":"activesupport","fixedVersion":"2.2.3"},{"ecosystem":"RubyGems","name":"activesupport","fixedVersion":"2.3.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/36600"},{"type":"ADVISORY","url":"http://secunia.com/advisories/36717"},{"type":"ADVISORY","url":"http://www.debian.org/security/2009/dsa-1887"},{"type":"ADVISORY","url":"http://www.vupen.com/english/advisories/2009/2544"},{"type":"ARTICLE","url":"http://weblog.rubyonrails.org/2009/9/4/xss-vulnerability-in-ruby-on-rails"},{"type":"FIX","url":"http://groups.google.com/group/rubyonrails-security/msg/7f57cd7794e1d1b4?dmode=source"},{"type":"FIX","url":"http://securitytracker.com/id?1022824"},{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=545063"},{"type":"WEB","url":"http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html"},{"type":"WEB","url":"http://support.apple.com/kb/HT4077"},{"type":"WEB","url":"http://www.osvdb.org/57666"},{"type":"WEB","url":"http://www.securityfocus.com/bid/36278"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/53036"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3009"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-8qrh-h9m2-5fvf"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activesupport/CVE-2009-3009.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:40:52.629215Z"}}