Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33167

Опубликовано: 23 мар. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (config.consider_all_requests_local = true), which is the default in development. Version 8.1.2.1 contains a patch.

A flaw was found in Action Pack, a component of the Rails framework. A remote attacker could exploit this vulnerability by crafting a malicious exception message. When this message is displayed on the debug exceptions page, the improper escaping of the message allows for the injection of arbitrary HTML and JavaScript, leading to Cross-Site Scripting (XSS). This primarily impacts applications with detailed exception pages enabled, which is the default setting in development environments.

Меры по смягчению последствий

To mitigate this issue, ensure that config.consider_all_requests_local is set to false in production environments for Rails applications. This configuration prevents the display of detailed exception pages, thereby eliminating the vector for this XSS vulnerability. This change may require a restart of the Rails application to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6rubygem-actionpackFix deferred
Red Hat Satellite 6satellite:el8/rubygem-actionpackFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2450552Rails: Action Pack: Action Pack: Cross-Site Scripting (XSS) via improper exception message escaping

EPSS

Процентиль: 33%
0.00401
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

ubuntu
5 месяцев назад

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.

nvd
5 месяцев назад

Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.

debian
5 месяцев назад

Action Pack is a Rubygem for building web applications on the Rails fr ...

github
5 месяцев назад

Rails has a possible XSS vulnerability in its Action Pack debug exceptions

EPSS

Процентиль: 33%
0.00401
Низкий

5.4 Medium

CVSS3