VDB

BDU%3A2025-00917

BDU%3A2025-00917 PUBLISHED CVSS 2.299999952316284 LOW

Уязвимость функции content_security_policy расширения Action Pack интерпретатора Ruby, позволяющая нарушителю проводить межсайтовые сценарные атаки(XSS)

Risk Scores

CVSS 4.0
2.299999952316284
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Affected Products

VendorProductVersions
Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Ruby TeamopenSUSE Tumbleweed, Red Hat 3scale API Management Platform, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Red Hat Satellite, Action Pack
railsrails>= 5.2.0, < 7.0.8.7, >= 7.1.0, < 7.1.5.1, >= 7.2.0, < 7.2.2.1

Timeline

  • Dec 10, 2024 CVE Published
  • Dec 10, 2024 PoC Published
  • Dec 11, 2024 PoC Published
  • Jan 31, 2025 CVE Updated
  • Feb 6, 2025 PoC Published
  • Oct 29, 2025 PoC Published
  • Oct 29, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›