{"id":"CVE-2012-6684","aliases":["GHSA-r23g-3qw4-gfh2"],"url":"https://o3.security/vulnerability/CVE-2012-6684","summary":"RedCloth Cross-site Scripting vulnerability","details":"Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.","published":"2015-01-08T01:59:01Z","modified":"2026-04-10T03:43:16.499600Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"RedCloth","fixedVersion":"4.3.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"http://jgarber.lighthouseapp.com/projects/13054-redcloth/tickets/243-xss"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2014/Dec/50"},{"type":"ADVISORY","url":"http://www.debian.org/security/2015/dsa-3168"},{"type":"ARTICLE","url":"http://co3k.org/blog/redcloth-unfixed-xss-en"},{"type":"ARTICLE","url":"http://seclists.org/fulldisclosure/2014/Dec/50"},{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2014/Dec/50"},{"type":"FIX","url":"https://gist.github.com/co3k/75b3cb416c342aa1414c"},{"type":"REPORT","url":"https://gist.github.com/co3k/75b3cb416c342aa1414c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:43:16.499600Z"}}