CVE Vulnerabilities

CVE-2024-28103

Published: Jun 04, 2024 | Modified: Jun 11, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
5.4 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM

Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.

Affected Software

Name Vendor Start Version End Version
Rails Rubyonrails 6.1.0 (including) 6.1.7.8 (excluding)
Rails Rubyonrails 7.0.0 (including) 7.0.8.4 (excluding)
Rails Rubyonrails 7.1.0 (including) 7.1.3.4 (excluding)
Rails Rubyonrails 7.2.0-beta1 (including) 7.2.0-beta1 (including)
Rails Ubuntu mantic *

References