CVE-2024-47888
published 2024-10-16CVE-2024-47888: Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a…
PriorityP337medium6.6CVSS 4.0
AVNACLATNPRNUINVCNVINVAHSCNSINSANEUCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.98%
58.7th percentile
Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the `plain_text_for_blockquote_node helper` in Action Text. Carefully crafted text can cause the `plain_text_for_blockquote_node` helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, or 7.2.1.1 or apply the relevant patch immediately. As a workaround, users can avoid calling `plain_text_for_blockquote_node` or upgrade to Ruby 3.2. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected. Rails 8.0.0.beta1 depends on Ruby 3.2 or greater so is unaffected.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rails | < rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm) | rails 2:6.1.7.10+dfsg-1~deb12u1 (bookworm) |
| rails | rails | — | — |
| rails | rails | — | — |
| rails | rails | — | — |
| rails | rails | — | — |
| rubyonrails | rails | >= 0 < 2:6.0.3.7+dfsg-2+deb11u3 | 2:6.0.3.7+dfsg-2+deb11u3 |
| rubyonrails | rails | >= 0 < 2:6.1.7.10+dfsg-1~deb12u1 | 2:6.1.7.10+dfsg-1~deb12u1 |
| rubyonrails | rails | >= 0 < 2:7.2.2.1+dfsg-1 | 2:7.2.2.1+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:7.2.2.1+dfsg-1 | 2:7.2.2.1+dfsg-1 |
| rubyonrails | rails | >= 0 < 2:4.2.6-1ubuntu0.1~esm1 | 2:4.2.6-1ubuntu0.1~esm1 |
| rubyonrails | rails | >= 0 < 2:4.2.10-0ubuntu4+esm1 | 2:4.2.10-0ubuntu4+esm1 |
| rubyonrails | rails | >= 0 < 2:5.2.3+dfsg-3ubuntu0.1~esm1 | 2:5.2.3+dfsg-3ubuntu0.1~esm1 |
| rubyonrails | rails | >= 0 < 2:6.1.4.1+dfsg-8ubuntu2+esm1 | 2:6.1.4.1+dfsg-8ubuntu2+esm1 |
CVSS provenance
nvdv4.06.6MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa6.6MEDIUM
osv6.6MEDIUM
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
vendor_ubuntu6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Rails vulnerabilities
vendor_ubuntu·2025-02-25·CVSS 6.6
CVE-2024-47887 [MEDIUM] Rails vulnerabilities
Title: Rails vulnerabilities
Summary: Several security issues were fixed in Rails.
It was discovered that Rails did not correctly handle parsing block
formats in email service layers. An attacker could possibly use this
issue to cause a denial of service. (CVE-2024-47889)
It was discovered that Rails did not correctly handle parsing block
quotes in rich text content. An attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 22.04 LTS.
(CVE-2024-47888)
It was discovered that Rails did not correctly handle parsing HTTP
token authentication headers. An attacker could possibly use this
issue to cause a denial of service. (CVE-2024-47887)
It was discovered that Rails did not correctly handle parsing query
parameters in web requests. An attacker
Red Hat
rubygem-actiontext: Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
vendor_redhat·2024-10-15·CVSS 6.6
CVE-2024-47888 [MEDIUM] CWE-1337 rubygem-actiontext: Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
rubygem-actiontext: Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the `plain_text_for_blockquote_node helper` in Action Text. Carefully crafted text can cause the `plain_text_for_blockquote_node` helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, or 7.2.1.1 or apply the relevant patch immediately. As a workaround, users can avoid calling `plain_text_for_blockquote_node` or upgrade to Ruby 3.2. Ruby 3.2 has mitigations for this problem, s
Debian
CVE-2024-47888: rails - Action Text brings rich text content and editing to Rails. Starting in version 6...
vendor_debian·2024·CVSS 6.6
CVE-2024-47888 [MEDIUM] CVE-2024-47888: rails - Action Text brings rich text content and editing to Rails. Starting in version 6...
Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the `plain_text_for_blockquote_node helper` in Action Text. Carefully crafted text can cause the `plain_text_for_blockquote_node` helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, or 7.2.1.1 or apply the relevant patch immediately. As a workaround, users can avoid calling `plain_text_for_blockquote_node` or upgrade to Ruby 3.2. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected. Rails 8.0.0.beta1 depends on Ruby 3.2
OSV
rails vulnerabilities
osv·2025-02-25·CVSS 6.6
CVE-2024-47889 [MEDIUM] rails vulnerabilities
rails vulnerabilities
It was discovered that Rails did not correctly handle parsing block
formats in email service layers. An attacker could possibly use this
issue to cause a denial of service. (CVE-2024-47889)
It was discovered that Rails did not correctly handle parsing block
quotes in rich text content. An attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 22.04 LTS.
(CVE-2024-47888)
It was discovered that Rails did not correctly handle parsing HTTP
token authentication headers. An attacker could possibly use this
issue to cause a denial of service. (CVE-2024-47887)
It was discovered that Rails did not correctly handle parsing query
parameters in web requests. An attacker could possibly use this issue
to cause a denial of service. (
OSV
CVE-2024-47888: Action Text brings rich text content and editing to Rails
osv·2024-10-16·CVSS 6.6
CVE-2024-47888 [MEDIUM] CVE-2024-47888: Action Text brings rich text content and editing to Rails
Action Text brings rich text content and editing to Rails. Starting in version 6.0.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the `plain_text_for_blockquote_node helper` in Action Text. Carefully crafted text can cause the `plain_text_for_blockquote_node` helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, or 7.2.1.1 or apply the relevant patch immediately. As a workaround, users can avoid calling `plain_text_for_blockquote_node` or upgrade to Ruby 3.2. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected. Rails 8.0.0.beta1 depends on Ruby 3.2
OSV
Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
osv·2024-10-15·CVSS 6.6
CVE-2024-47888 [MEDIUM] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
There is a possible ReDoS vulnerability in the plain_text_for_blockquote_node helper in Action Text. This vulnerability has been assigned the CVE identifier CVE-2024-47888.
Impact
Carefully crafted text can cause the plain_text_for_blockquote_node helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade or apply the relevant patch immediately.
Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected. Rails 8.0.0.beta1 depends on Ruby 3.2 or greater so is unaffected.
Releases
The fixed releases are available at the normal locations.
Workarounds
Users can avoid calling `pl
GHSA
Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
ghsa·2024-10-15·CVSS 6.6
CVE-2024-47888 [MEDIUM] CWE-1333 Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
There is a possible ReDoS vulnerability in the plain_text_for_blockquote_node helper in Action Text. This vulnerability has been assigned the CVE identifier CVE-2024-47888.
Impact
Carefully crafted text can cause the plain_text_for_blockquote_node helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade or apply the relevant patch immediately.
Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected. Rails 8.0.0.beta1 depends on Ruby 3.2 or greater so is unaffected.
Releases
The fixed releases are available at the normal locations.
Workarounds
Users can avoid calling `pl
No detection rules found.
No public exploits indexed.
HackerOne
[CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
hackerone·2024-11-28·CVSS 6.6
CVE-2024-47888 [MEDIUM] [CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
[CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
I made a report at https://hackerone.com/reports/2389431
https://discuss.rubyonrails.org/t/cve-2024-47888-possible-redos-vulnerability-in-plain-text-for-blockquote-node-in-action-text/87696
> There is a possible ReDoS vulnerability in the plain_text_for_blockquote_node helper in Action Text. This vulnerability has been assigned the CVE identifier CVE-2024-47888.
## Impact
> Carefully crafted text can cause the plain_text_for_blockquote_node helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability.
Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
There is a possible ReDoS vulnerability in the plain_text_for_blockquote_node helper in
Bugzilla
CVE-2024-47888 rubygem-actiontext: Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
bugzilla·2024-10-16·CVSS 6.6
CVE-2024-47888 [MEDIUM] CVE-2024-47888 rubygem-actiontext: Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
CVE-2024-47888 rubygem-actiontext: Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
There is a possible ReDoS vulnerability in the plain_text_for_blockquote_node helper in Action Text. This vulnerability has been assigned the CVE identifier CVE-2024-47888.
Impact
Carefully crafted text can cause the plain_text_for_blockquote_node helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade or apply the relevant patch immediately.
Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected. Rails 8.0.0.beta1 depends on Ruby 3.2 or greater so is unaffected.
Releases
The fixed releases are available at the normal locations.
Work
https://github.com/rails/rails/commit/4f4312b21a6448336de7c7ab0c4d94b378def468https://github.com/rails/rails/commit/727b0946c3cab04b825c039435eac963d4e91822https://github.com/rails/rails/commit/ba286c0a310b7f19cf5cac2a7a4c9def5cf9882ehttps://github.com/rails/rails/commit/de0df7caebd9cb238a6f10dca462dc5f8d5e98b5https://github.com/rails/rails/security/advisories/GHSA-wwhv-wxv9-rpgw
2024-10-16
Published