CVE-2022-22577Cross-site Scripting in Actionpack

Severity
6.1MEDIUMNVD
EPSS
0.3%
top 47.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 26

Description

An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages4 packages

NVDrubyonrails/actionpack5.2.05.2.7.1+3
RubyGemsactionpack_project/actionpack5.2.05.2.7.1+3
Debianrubyonrails/rails< 2:6.0.3.7+dfsg-2+deb11u1+3
CVEListV5https/github.com_rails_rails7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1

Also affects: Debian Linux 10.0

Patches

🔴Vulnerability Details

4
CVEList
CVE-2022-22577: An XSS Vulnerability in Action Pack >= 52022-05-26
OSV
CVE-2022-22577: An XSS Vulnerability in Action Pack >= 52022-05-26
OSV
Cross-site Scripting Vulnerability in Action Pack2022-04-27
GHSA
Cross-site Scripting Vulnerability in Action Pack2022-04-27

📋Vendor Advisories

2
Red Hat
rubygem-actionpack: Possible cross-site scripting vulnerability in Action Pack2022-04-27
Debian
CVE-2022-22577: rails - An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an att...2022
CVE-2022-22577 — Cross-site Scripting in Actionpack | cvebase