Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgm4-439c-5jp6

Опубликовано: 23 мар. 2026
Источник: github
Github: Прошло ревью
CVSS4: 1.3

Описание

Rails has a possible XSS vulnerability in its Action Pack debug exceptions

Impact

The debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (config.consider_all_requests_local = true), which is the default in development.

Releases

The fixed releases are available at the normal locations.

Credit

This issue was responsibly reported by Hackerone researcher fbettag.

Пакеты

Наименование

actionpack

rubygems
Затронутые версииВерсия исправления

>= 8.1.0, < 8.1.2.1

8.1.2.1

EPSS

Процентиль: 33%
0.00401
Низкий

1.3 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
5 месяцев назад

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.

CVSS3: 5.4
redhat
5 месяцев назад

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.

nvd
5 месяцев назад

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.

debian
5 месяцев назад

Action Pack is a Rubygem for building web applications on the Rails fr ...

EPSS

Процентиль: 33%
0.00401
Низкий

1.3 Low

CVSS4

Дефекты

CWE-79