Cross-site Scripting in view_component
CVE-2022-24722
What is CVE-2022-24722?
VIewComponent is a framework for building view components in Ruby on Rails. Versions prior to 2.31.2 and 2.49.1 contain a cross-site scripting vulnerability that has the potential to impact anyone using translations with the view_component gem. Data received via user input and passed as an interpolation argument to the translate method is not properly sanitized before display. Versions 2.31.2 and 2.49.1 have been released and fully mitigate the vulnerability. As a workaround, avoid passing user input to the translate function, or sanitize the inputs before passing them.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
view_component >= 2.31.0, < 2.31.2 < 2.31.0, 2.31.2
view_component >= 2.32.0, < 2.49.1 < 2.32.0, 2.49.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved