Vulnerability Description
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rubyonrails | Rails | >= 6.1.0, < 6.1.7.8 |
Related Weaknesses (CWE)
References
- https://github.com/rails/rails/commit/35858f1d9d57f6c4050a8d9ab754bd5d088b4523Patch
- https://github.com/rails/rails/security/advisories/GHSA-fwhr-88qx-h9g7Vendor Advisory
- https://github.com/rails/rails/commit/35858f1d9d57f6c4050a8d9ab754bd5d088b4523Patch
- https://github.com/rails/rails/security/advisories/GHSA-fwhr-88qx-h9g7Vendor Advisory
- https://security.netapp.com/advisory/ntap-20241206-0002/
FAQ
What is CVE-2024-28103?
CVE-2024-28103 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This...
How severe is CVE-2024-28103?
CVE-2024-28103 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28103?
Check the references section above for vendor advisories and patch information. Affected products include: Rubyonrails Rails.