CVE-2024-26144
published 2024-02-27CVE-2024-26144: Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
1.12%
62.7th percentile
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm) | rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm) |
| rails | activestorage | >= 5.2.0 < 6.1.7.7 | 6.1.7.7 |
| rails | activestorage | >= 7.0.0 < 7.0.8.1 | 7.0.8.1 |
| rails | rails | — | — |
| rails | rails | — | — |
| rubyonrails | rails | >= 0 < 2:6.1.7.10+dfsg-1~deb12u1 | 2:6.1.7.10+dfsg-1~deb12u1 |
| rubyonrails | rails | >= 0 < 2:7.2.2.1+dfsg-1 | 2:7.2.2.1+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:7.2.2.1+dfsg-1 | 2:7.2.2.1+dfsg-1 |
| rubyonrails | rails | >= 5.2.0 < 6.1.7.7 | 6.1.7.7 |
| rubyonrails | rails | >= 7.0.0 < 7.1.0 | 7.1.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
ghsa5.3MEDIUM
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Rails has possible Sensitive Session Information Leak in Active Storage
ghsa·2024-02-27·CVSS 5.3
CVE-2024-26144 [MEDIUM] CWE-200 Rails has possible Sensitive Session Information Leak in Active Storage
Rails has possible Sensitive Session Information Leak in Active Storage
# Possible Sensitive Session Information Leak in Active Storage
There is a possible sensitive session information leak in Active Storage. By
default, Active Storage sends a `Set-Cookie` header along with the user's
session cookie when serving blobs. It also sets `Cache-Control` to public.
Certain proxies may cache the Set-Cookie, leading to an information leak.
This vulnerability has been assigned the CVE identifier CVE-2024-26144.
Versions Affected: >= 5.2.0, 7.1.0
Fixed Versions: 7.0.8.1, 6.1.7.7
Impact
A proxy which chooses to caches this request can cause users to share
sessions. This may include a user receiving an attacker's session or vice
versa.
This was patched in 7.1.0 but not previously identified as a
OSV
CVE-2024-26144: Rails is a web-application framework
osv·2024-02-27·CVSS 5.3
CVE-2024-26144 [MEDIUM] CVE-2024-26144: Rails is a web-application framework
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.
OSV
Rails has possible Sensitive Session Information Leak in Active Storage
osv·2024-02-27·CVSS 5.3
CVE-2024-26144 [MEDIUM] Rails has possible Sensitive Session Information Leak in Active Storage
Rails has possible Sensitive Session Information Leak in Active Storage
# Possible Sensitive Session Information Leak in Active Storage
There is a possible sensitive session information leak in Active Storage. By
default, Active Storage sends a `Set-Cookie` header along with the user's
session cookie when serving blobs. It also sets `Cache-Control` to public.
Certain proxies may cache the Set-Cookie, leading to an information leak.
This vulnerability has been assigned the CVE identifier CVE-2024-26144.
Versions Affected: >= 5.2.0, 7.1.0
Fixed Versions: 7.0.8.1, 6.1.7.7
Impact
A proxy which chooses to caches this request can cause users to share
sessions. This may include a user receiving an attacker's session or vice
versa.
This was patched in 7.1.0 but not previously identified as a
Red Hat
rubygem-activestorage: Possible Sensitive Session Information Leak in Active Storage
vendor_redhat·2024-02-25·CVSS 5.3
CVE-2024-26144 [MEDIUM] CWE-200 rubygem-activestorage: Possible Sensitive Session Information Leak in Active Storage
rubygem-activestorage: Possible Sensitive Session Information Leak in Active Storage
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.
A flaw was found in Active Storage that may lead to a sensitive session information leak. By default, Active Storage sends a `Set-Cookie` header along with the user’s session cookie when serving blobs and sets `Cache-Control` to public. Certain proxies may cache `Set-Cookie`, leading to an informat
Debian
CVE-2024-26144: rails - Rails is a web-application framework. Starting with version 5.2.0, there is a po...
vendor_debian·2024·CVSS 5.3
CVE-2024-26144 [MEDIUM] CVE-2024-26144: rails - Rails is a web-application framework. Starting with version 5.2.0, there is a po...
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.
Scope: local
bookworm: resolved (fixed in 2:6.1.7.10+dfsg-1~deb12u1)
bullseye: resolved
forky: resolved (fixed in 2:7.2.2.1+dfsg-1)
sid: resolved (fixed in 2:7.2.2.1+dfsg-1)
trixie: resolved (fixed in 2:7.2.2.1+dfsg-1)
No detection rules found.
No public exploits indexed.
https://discuss.rubyonrails.org/t/possible-sensitive-session-information-leak-in-active-storage/84945https://github.com/rails/rails/commit/723f54566023e91060a67b03353e7c03e7436433https://github.com/rails/rails/commit/78fe149509fac5b05e54187aaaef216fbb5fd0d3https://github.com/rails/rails/security/advisories/GHSA-8h22-8cf7-hq6ghttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2024-26144.ymlhttps://security.netapp.com/advisory/ntap-20240510-0013/https://discuss.rubyonrails.org/t/possible-sensitive-session-information-leak-in-active-storage/84945https://github.com/rails/rails/commit/723f54566023e91060a67b03353e7c03e7436433https://github.com/rails/rails/commit/78fe149509fac5b05e54187aaaef216fbb5fd0d3https://github.com/rails/rails/security/advisories/GHSA-8h22-8cf7-hq6ghttps://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2024-26144.ymlhttps://security.netapp.com/advisory/ntap-20240510-0013/
2024-02-27
Published