CVE-2024-28103
MEDIUMRails < 6.1.7.8 - Improper Input Validation
Title source: ruleDescription
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.
Scores
CVSS v3
5.4
EPSS
0.0083
EPSS Percentile
74.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Classification
CWE
CWE-20
Status
published
Affected Products (3)
rubyonrails/rails
< 6.1.7.8
rubyonrails/rails
rubygems/actionpack
< 6.1.7.8RubyGems
Timeline
Published
Jun 04, 2024
Tracked Since
Feb 18, 2026