Логотип exploitDog
bind:CVE-2022-23633
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-23633

Количество 6

Количество 6

ubuntu логотип

CVE-2022-23633

почти 4 года назад

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2022-23633

почти 4 года назад

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-23633

почти 4 года назад

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2022-23633

почти 4 года назад

Action Pack is a framework for handling and responding to web requests ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-wh98-p28r-vrc9

почти 4 года назад

Exposure of information in Action Pack

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2108-1

больше 3 лет назад

Security update for rubygem-actionpack-5_1, rubygem-activesupport-5_1

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 7.4
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 5.9
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS3: 7.4
0%
Низкий
почти 4 года назад
debian логотип
CVE-2022-23633

Action Pack is a framework for handling and responding to web requests ...

CVSS3: 7.4
0%
Низкий
почти 4 года назад
github логотип
GHSA-wh98-p28r-vrc9

Exposure of information in Action Pack

CVSS3: 7.4
0%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:2108-1

Security update for rubygem-actionpack-5_1, rubygem-activesupport-5_1

больше 3 лет назад

Уязвимостей на страницу