Possible ReDoS Vulnerability in Rails Accept Header Parsing
CVE-2024-26142

7.5HIGH

Key Information:

Vendor

Rails

Status
Vendor
CVE Published:
27 February 2024

What is CVE-2024-26142?

The Rails web-application framework has a vulnerability in its Action Dispatch component, specifically related to parsing Accept headers. This vulnerability arises in versions starting from 7.1.0 and has been addressed in the subsequent release, 7.1.3.1. Applications utilizing Ruby 3.2 or above are not impacted due to the mitigations present in that version of Ruby. It is recommended that users update their Rails framework to the latest version to prevent potential exploitation of this vulnerability.

Affected Version(s)

rails >= 7.1.0, < 7.1.3.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.