XSS Vulnerability in Action Pack by Ruby on Rails
CVE-2022-22577

6.1MEDIUM

Key Information:

Vendor
CVE Published:
26 May 2022

What is CVE-2022-22577?

An XSS vulnerability exists in Action Pack versions ranging from 5.2.0 to below 5.2.0, allowing an attacker to bypass Content Security Policy (CSP) protections for non-HTML responses. This could potentially lead to the execution of malicious scripts in the context of other users' browsers. It is crucial for developers using these versions to implement necessary patches and security measures to mitigate the risk of exploitation.

Affected Version(s)

https://github.com/rails/rails 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-22577 : XSS Vulnerability in Action Pack by Ruby on Rails