CVE-2022-22577
published 2022-05-26CVE-2022-22577: An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.59%
73.0th percentile
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 5.2.0 < 5.2.7.1 | 5.2.7.1 |
| actionpack_project | actionpack | >= 6.0.0 < 6.0.4.8 | 6.0.4.8 |
| actionpack_project | actionpack | >= 6.1.0 < 6.1.5.1 | 6.1.5.1 |
| actionpack_project | actionpack | >= 7.0.0 < 7.0.2.4 | 7.0.2.4 |
| debian | debian_linux | — | — |
| debian | rails | < rails 2:6.1.6.1+dfsg-1 (bookworm) | rails 2:6.1.6.1+dfsg-1 (bookworm) |
| https | github.com_rails_rails | — | — |
| rubyonrails | actionpack | >= 5.2.0 < 5.2.7.1 | 5.2.7.1 |
| rubyonrails | actionpack | >= 6.0.0 < 6.0.4.8 | 6.0.4.8 |
| rubyonrails | actionpack | >= 6.1.0 < 6.1.5.1 | 6.1.5.1 |
| rubyonrails | actionpack | >= 7.0.0 < 7.0.2.4 | 7.0.2.4 |
| rubyonrails | rails | >= 0 < 2:6.0.3.7+dfsg-2+deb11u1 | 2:6.0.3.7+dfsg-2+deb11u1 |
| rubyonrails | rails | >= 0 < 2:6.1.6.1+dfsg-1 | 2:6.1.6.1+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.6.1+dfsg-1 | 2:6.1.6.1+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:6.1.6.1+dfsg-1 | 2:6.1.6.1+dfsg-1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
rubygem-actionpack: Possible cross-site scripting vulnerability in Action Pack
vendor_redhat·2022-04-27·CVSS 6.1
CVE-2022-22577 [MEDIUM] CWE-79 rubygem-actionpack: Possible cross-site scripting vulnerability in Action Pack
rubygem-actionpack: Possible cross-site scripting vulnerability in Action Pack
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
A flaw was found in rubygem-actionpack where CSP headers were sent with responses that Rails considered "HTML" responses. This flaw allows an attacker to leave API requests without CSP headers and perform a Cross-site scripting attack.
Package: actionpack (CloudForms Management Engine 5) - Out of support scope
Package: actionpack (Red Hat 3scale API Management Platform 2) - Will not fix
Debian
CVE-2022-22577: rails - An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an att...
vendor_debian·2022·CVSS 6.1
CVE-2022-22577 [MEDIUM] CVE-2022-22577: rails - An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an att...
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
Scope: local
bookworm: resolved (fixed in 2:6.1.6.1+dfsg-1)
bullseye: resolved (fixed in 2:6.0.3.7+dfsg-2+deb11u1)
forky: resolved (fixed in 2:6.1.6.1+dfsg-1)
sid: resolved (fixed in 2:6.1.6.1+dfsg-1)
trixie: resolved (fixed in 2:6.1.6.1+dfsg-1)
OSV
CVE-2022-22577: An XSS Vulnerability in Action Pack >= 5
osv·2022-05-26·CVSS 6.1
CVE-2022-22577 [MEDIUM] CVE-2022-22577: An XSS Vulnerability in Action Pack >= 5
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
OSV
Cross-site Scripting Vulnerability in Action Pack
osv·2022-04-27·CVSS 6.1
CVE-2022-22577 [MEDIUM] Cross-site Scripting Vulnerability in Action Pack
Cross-site Scripting Vulnerability in Action Pack
There is a possible XSS vulnerability in Rails / Action Pack. This vulnerability has been
assigned the CVE identifier CVE-2022-22577.
Versions Affected: >= 5.2.0
Not affected: < 5.2.0
Fixed Versions: 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1
## Impact
CSP headers were only sent along with responses that Rails considered as
"HTML" responses. This left API requests without CSP headers, which could
possibly expose users to XSS attacks.
## Releases
The FIXED releases are available at the normal locations.
## Workarounds
Set a CSP for your API responses manually.
GHSA
Cross-site Scripting Vulnerability in Action Pack
ghsa·2022-04-27·CVSS 6.1
CVE-2022-22577 [MEDIUM] CWE-79 Cross-site Scripting Vulnerability in Action Pack
Cross-site Scripting Vulnerability in Action Pack
There is a possible XSS vulnerability in Rails / Action Pack. This vulnerability has been
assigned the CVE identifier CVE-2022-22577.
Versions Affected: >= 5.2.0
Not affected: < 5.2.0
Fixed Versions: 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1
## Impact
CSP headers were only sent along with responses that Rails considered as
"HTML" responses. This left API requests without CSP headers, which could
possibly expose users to XSS attacks.
## Releases
The FIXED releases are available at the normal locations.
## Workarounds
Set a CSP for your API responses manually.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://discuss.rubyonrails.org/t/cve-2022-22577-possible-xss-vulnerability-in-action-pack/80533https://lists.debian.org/debian-lts-announce/2022/09/msg00002.htmlhttps://security.netapp.com/advisory/ntap-20221118-0002/https://www.debian.org/security/2023/dsa-5372https://discuss.rubyonrails.org/t/cve-2022-22577-possible-xss-vulnerability-in-action-pack/80533https://lists.debian.org/debian-lts-announce/2022/09/msg00002.htmlhttps://security.netapp.com/advisory/ntap-20221118-0002/https://www.debian.org/security/2023/dsa-5372
2022-05-26
Published