VDB
WID-SEC-W-2024-0462
WID-SEC-W-2024-0462
PUBLISHED
Ruby on Rails ist ein in der Programmiersprache Ruby geschriebenes und quelloffenes Web Application Framework.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source Ruby on Rails 7.1.3.2 | ||
| Red Hat Enterprise Linux | ||
| Open Source Ruby on Rails <7.1.3.2 | ||
| Open Source Ruby on Rails <6.1.7.7 | ||
| SUSE openSUSE | ||
| IBM License Metric Tool 9.2 | ||
| Debian Linux | ||
| Open Source Ruby on Rails 7.0.8.1 | ||
| Open Source Ruby on Rails <7.0.8.1 | ||
| Open Source Ruby on Rails 6.1.7.7 |
Exploit Intelligence
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0462.json (circl)
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0462 (circl)
- https://rubyonrails.org/2024/2/21/Rails-Versions-6-1-7-7-7-0-8-1-and-7-1-3-2-have-been-released (circl)
- https://discuss.rubyonrails.org/t/possible-xss-vulnerability-in-action-controller/84947 (circl)
- https://discuss.rubyonrails.org/t/possible-redos-vulnerability-in-accept-header-parsing-in-action-dispatch/84946 (circl)
- https://discuss.rubyonrails.org/t/possible-sensitive-session-information-leak-in-active-storage/84945 (circl)
- https://www.ibm.com/support/pages/node/7144239 (circl)
- https://access.redhat.com/errata/RHSA-2024:10806 (circl)
- https://lists.debian.org/debian-security-announce/2025/msg00043.html (circl)
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3C5WPU2RXUSPKAI3EANLIGCY34ZDBZ4Y/ (circl)
Timeline
- Feb 21, 2024 CVE Published
- May 18, 2025 CVE Updated
- Mar 31, 2026 Distribution Patch
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-0462.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-0462 advisory
- https://rubyonrails.org/2024/2/21/Rails-Versions-6-1-7-7-7-0-8-1-and-7-1-3-2-have-been-released url
- https://discuss.rubyonrails.org/t/possible-xss-vulnerability-in-action-controller/84947 url
- https://discuss.rubyonrails.org/t/possible-redos-vulnerability-in-accept-header-parsing-in-action-dispatch/84946 url
- https://discuss.rubyonrails.org/t/possible-sensitive-session-information-leak-in-active-storage/84945 url
- https://www.ibm.com/support/pages/node/7144239 url
- https://access.redhat.com/errata/RHSA-2024:10806 url
- https://lists.debian.org/debian-security-announce/2025/msg00043.html url
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/3C5WPU2RXUSPKAI3EANLIGCY34ZDBZ4Y/ url