Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2022-23633

больше 4 лет назад

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-23633

больше 4 лет назад

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-23633

больше 4 лет назад

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2022-23633

больше 4 лет назад

Action Pack is a framework for handling and responding to web requests ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-wh98-p28r-vrc9

больше 4 лет назад

Exposure of information in Action Pack

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2108-1

около 4 лет назад

Security update for rubygem-actionpack-5_1, rubygem-activesupport-5_1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 7.4
2%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 7.4
2%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests ...

CVSS3: 7.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-wh98-p28r-vrc9

Exposure of information in Action Pack

CVSS3: 7.4
2%
Низкий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:2108-1

Security update for rubygem-actionpack-5_1, rubygem-activesupport-5_1

около 4 лет назад

Уязвимостей на страницу