VDB
BDU%3A2025-00917
BDU%3A2025-00917
PUBLISHED
CVSS 2.299999952316284 LOW
Уязвимость функции content_security_policy расширения Action Pack интерпретатора Ruby, позволяющая нарушителю проводить межсайтовые сценарные атаки(XSS)
Risk Scores
CVSS 4.0
2.299999952316284
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Ruby Team | openSUSE Tumbleweed, Red Hat 3scale API Management Platform, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), Red Hat Satellite, Action Pack | |
| rails | rails | >= 5.2.0, < 7.0.8.7, >= 7.1.0, < 7.1.5.1, >= 7.2.0, < 7.2.2.1 |
Timeline
- Dec 10, 2024 CVE Published
- Dec 10, 2024 PoC Published
- Dec 11, 2024 PoC Published
- Jan 31, 2025 CVE Updated
- Feb 6, 2025 PoC Published
- Oct 29, 2025 PoC Published
- Oct 29, 2025 PoC Published
References
- https://github.com/rails/rails/commit/2e3f41e4538b9ca1044357f6644f037bbb7c6c49 url
- https://github.com/rails/rails/commit/3da2479cfe1e00177114b17e496213c40d286b3a url
- https://github.com/rails/rails/commit/5558e72f22fc69c1c407b31ac5fb3b4ce087b542 url
- https://github.com/rails/rails/commit/cb16a3bb515b5d769f73926d9757270ace691f1d url
- https://security.netapp.com/advisory/ntap-20250306-0010/ url
- https://redos.red-soft.ru/support/secure/ url
- https://redos.red-soft.ru/support/secure/uyazvimosti/uyazvimost-rubygem-actionpack-cve-2024-54133/?sphrase_id=643985 advisory
- https://github.com/rails/rails/commit/2e3f41e4538b9ca1044357f6644f037bbb7c6c49_x0001_ advisory
- https://github.com/rails/rails/commit/3da2479cfe1e00177114b17e496213c40d286b3a_x0001_ advisory
- https://github.com/rails/rails/commit/5558e72f22fc69c1c407b31ac5fb3b4ce087b542_x0001_ advisory
- https://github.com/rails/rails/commit/cb16a3bb515b5d769f73926d9757270ace691f1d_x0001_ advisory
- https://github.com/rails/rails/security/advisories/GHSA-vfm5-rmrh-j26v advisory
- https://security-tracker.debian.org/tracker/CVE-2024-54133 advisory
- https://access.redhat.com/security/cve/cve-2024-54133 advisory
- https://www.suse.com/security/cve/CVE-2024-54133.html advisory