Ruby on Rails contains a flaw that allows a remote cross-site scripting (XSS)
attack. This flaw exists because the application does not validate manually
generated 'select tag options' upon submission to
actionpack/lib/action_view/helpers/form_options_helper.rb. This may allow a
user to create a specially crafted request that would execute arbitrary
script code in a user's browser within the trust relationship between their
browser and the server.

Am I vulnerable?

The constraints below list the versions that this vulnerability is patched in, and versions that are unaffected. If a patch is ready but unrealeased, then it is pending.

Affected package information

Package Patched in Unaffected in
actionpack ~> 3.0.12,~> 3.1.4,>= 3.2.2 None