Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-26142

Опубликовано: 27 фев. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:*
Версия от 7.1.0 (включая) до 7.1.3.1 (исключая)
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
Версия до 3.2.0 (исключая)

EPSS

Процентиль: 82%
0.01701
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-1333

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

CVSS3: 5.9
redhat
почти 2 года назад

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

CVSS3: 7.5
debian
почти 2 года назад

Rails is a web-application framework. Starting in version 7.1.0, there ...

github
почти 2 года назад

Rails has possible ReDoS vulnerability in Accept header parsing in Action Dispatch

EPSS

Процентиль: 82%
0.01701
Низкий

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-1333