Medium severity6.1NVD Advisory· Published Jan 19, 2018· Updated Jun 17, 2026
CVE-2017-12097
CVE-2017-12097
Description
An exploitable cross site scripting (XSS) vulnerability exists in the filter functionality of the delayed_job_web rails gem version 1.4. A specially crafted URL can cause an XSS flaw resulting in an attacker being able to execute arbitrary javascript on the victim's browser. An attacker can phish an authenticated user to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
delayed_job_webRubyGems | >= 1.2.9, < 1.4.2 | 1.4.2 |
Affected products
3- cpe:2.3:a:delayed_job_web_project:delayed_job_web:1.4:*:*:*:*:ruby:*:*
- Talos/delayed_job_web rails gemv5Range: delayed\_job\_web 1.4
Patches
Vulnerability mechanics
References
8- www.talosintelligence.com/vulnerability_reports/TALOS-2017-0449nvdExploitThird Party AdvisoryWEB
- www.securityfocus.com/bid/102484nvdBroken LinkThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-w7q9-xr2x-wh7xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-12097ghsaADVISORY
- github.com/ejschmitt/delayed_job_web/commit/6bcb10e61ea2b9a44ffa16be8536dff46ad51449ghsaWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/delayed_job_web/CVE-2017-12097.ymlghsaWEB
- rubygems.org/gems/delayed_job_web/versions/1.4ghsaWEB
- web.archive.org/web/20200227132840/http://www.securityfocus.com/bid/102484ghsaWEB
News mentions
0No linked articles in our index yet.