Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28103

Опубликовано: 04 июн. 2024
Источник: redhat
CVSS3: 5.4

Описание

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.

A flaw was found in rubygem-actionpack. Since version 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML-related Content-Type. This vulnerability is fixed in versions 6.1.7.8, 7.0.8.2, and 7.1.3.3.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp-zync-containerNot affected
Red Hat Satellite 6rubygem-actionpackAffected
Red Hat Satellite 6satellite:el8/rubygem-actionpackAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2290530rubygem-actionpack: Missing security headers in Action Pack on non-HTML responses

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 1 года назад

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.

CVSS3: 5.4
nvd
около 1 года назад

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.

CVSS3: 5.4
debian
около 1 года назад

Action Pack is a framework for handling and responding to web requests ...

suse-cvrf
около 1 года назад

Security update for rmt-server

suse-cvrf
около 1 года назад

Security update for rmt-server

5.4 Medium

CVSS3