CVE-2024-28103Improper Input Validation in Rails

Severity
9.8CRITICALNVD
CNA5.4
EPSS
0.8%
top 25.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4

Description

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages4 packages

RubyGemsactionpack_project/actionpack6.1.06.1.7.8+3
NVDrubyonrails/rails6.1.06.1.7.8+3
Debianrubyonrails/rails< 2:6.1.7.10+dfsg-1~deb12u1+2
CVEListV5rails/rails4 versions+3

Patches

🔴Vulnerability Details

4
OSV
Missing security headers in Action Pack on non-HTML responses2024-06-04
CVEList
Action Pack is missing security headers on non-HTML responses2024-06-04
GHSA
Missing security headers in Action Pack on non-HTML responses2024-06-04
OSV
CVE-2024-28103: Action Pack is a framework for handling and responding to web requests2024-06-04

📋Vendor Advisories

2
Red Hat
rubygem-actionpack: Missing security headers in Action Pack on non-HTML responses2024-06-04
Debian
CVE-2024-28103: rails - Action Pack is a framework for handling and responding to web requests. Since 6....2024
CVE-2024-28103 — Improper Input Validation in Rails | cvebase