VDB

BIT-RAILS-2024-26142

BIT-RAILS-2024-26142 PUBLISHED CVSS 7.5 HIGH

Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
railsrails>= 7.1.0, < 7.1.3.1
railsrails7.1.0

Timeline

  • Feb 27, 2024 CVE Published
  • Feb 27, 2024 PoC Published
  • Feb 27, 2024 PoC Published
  • May 23, 2024 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›