Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-26142

Опубликовано: 27 фев. 2024
Источник: debian
EPSS Низкий

Описание

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsnot-affectedpackage

Примечания

  • https://github.com/rails/rails/security/advisories/GHSA-jjhx-jhvp-74wq

  • https://github.com/rails/rails/commit/b4d3bfb5ed8a5b5a90aad3a3b28860c7a931e272 (v7.1.3.1)

EPSS

Процентиль: 85%
0.02644
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

CVSS3: 5.9
redhat
почти 2 года назад

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

CVSS3: 7.5
nvd
почти 2 года назад

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

github
почти 2 года назад

Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch

EPSS

Процентиль: 85%
0.02644
Низкий