XSS Vulnerability in Action Pack by Ruby on Rails
CVE-2022-22577
6.1MEDIUM
Key Information:
- Vendor
Rubyonrails
- Vendor
- CVE Published:
- 26 May 2022
What is CVE-2022-22577?
An XSS vulnerability exists in Action Pack versions ranging from 5.2.0 to below 5.2.0, allowing an attacker to bypass Content Security Policy (CSP) protections for non-HTML responses. This could potentially lead to the execution of malicious scripts in the context of other users' browsers. It is crucial for developers using these versions to implement necessary patches and security measures to mitigate the risk of exploitation.
Affected Version(s)
https://github.com/rails/rails 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1