CVE-2018-16471
Estado: ModificadaMedia (6.1)—
There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 6.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.89%
- Percentil entre todas las CVEs puntuadas: 79
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-79
- CWE-79
Referencias
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html
- https://groups.google.com/forum/#%21topic/rubyonrails-security/GKsAFT924Ag
- https://lists.debian.org/debian-lts-announce/2018/11/msg00022.html
- https://usn.ubuntu.com/4089-1/
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00032.html
- http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html
- https://groups.google.com/forum/#%21topic/rubyonrails-security/GKsAFT924Ag
- https://lists.debian.org/debian-lts-announce/2018/11/msg00022.html
- https://usn.ubuntu.com/4089-1/
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-16471",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "support@hackerone.com",
"affectedData": [
{
"vendor": "Rack",
"product": "Rack",
"versions": [
{
"status": "affected",
"version": "2.0.6, 1.6.11"
}
]
}
]
}
],
"published": "2018-11-13T23:29:00.310",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00032.html",
"source": "support@hackerone.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html",
"source": "support@hackerone.com"
},
{
"url": "https://groups.google.com/forum/#%21topic/rubyonrails-security/GKsAFT924Ag",
"source": "support@hackerone.com"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2018/11/msg00022.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "support@hackerone.com"
},
{
"url": "https://usn.ubuntu.com/4089-1/",
"source": "support@hackerone.com"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00032.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00016.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://groups.google.com/forum/#%21topic/rubyonrails-security/GKsAFT924Ag",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2018/11/msg00022.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://usn.ubuntu.com/4089-1/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "support@hackerone.com",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "There is a possible XSS vulnerability in Rack before 2.0.6 and 1.6.11. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`. Applications that expect the scheme to be limited to 'http' or 'https' and do not escape the return value could be vulnerable to an XSS attack. Note that applications using the normal escaping mechanisms provided by Rails may not impacted, but applications that bypass the escaping mechanisms, or do not use them may be vulnerable."
},
{
"lang": "es",
"value": "Hay una posible vulnerabilidad Cross-Site Scripting (XSS) en Rack en versiones anteriores a la 2.0.6 y la 1.6.11. Las peticiones cuidadosamente manipuladas pueden provocar un impacto en los datos devueltos por el método \"scheme\" en \"Rack::Request\". Las aplicaciones que esperan que el esquema esté limitado a \"http\" o \"https\" y que no escapan el valor de retorno podrían ser vulnerables a un ataque Cross-Site Scripting (XSS). Nótese que las aplicaciones que emplean los mecanismos de escape normales proporcionados por Rails podrían no haberse visto impactados, pero las aplicaciones que omiten los mecanismos de escape o que no los emplean podrían ser vulnerables."
}
],
"lastModified": "2026-06-17T01:44:21.053",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "88141B61-D802-4C96-B46D-92A2D808A528",
"versionEndExcluding": "1.6.11",
"versionStartIncluding": "1.6.0"
},
{
"criteria": "cpe:2.3:a:rack_project:rack:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "854E2437-A12B-4B29-9786-C78DF3204A61",
"versionEndExcluding": "2.0.6",
"versionStartIncluding": "2.0.0"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "support@hackerone.com"
}