Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mm33-5vfq-3mm3

Опубликовано: 27 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site Scripting Vulnerability in Action Pack

There is a possible XSS vulnerability in Rails / Action Pack. This vulnerability has been assigned the CVE identifier CVE-2022-22577.

Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1

Impact

CSP headers were only sent along with responses that Rails considered as "HTML" responses. This left API requests without CSP headers, which could possibly expose users to XSS attacks.

Releases

The FIXED releases are available at the normal locations.

Workarounds

Set a CSP for your API responses manually.

Пакеты

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 5.2.0, <= 5.2.7.0

5.2.7.1

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 6.0.0, <= 6.0.4.7

6.0.4.8

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 6.1.0, <= 6.1.5.0

6.1.5.1

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 7.0.0, <= 7.0.2.3

7.0.2.4

EPSS

Процентиль: 52%
0.00287
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.

CVSS3: 7.5
redhat
почти 4 года назад

An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.

CVSS3: 6.1
nvd
больше 3 лет назад

An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.

CVSS3: 6.1
debian
больше 3 лет назад

An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could al ...

EPSS

Процентиль: 52%
0.00287
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79