Untriaged
Rails has a possible XSS vulnerability in its Action Pack debug exceptions
Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.
References
-
https://github.com/rails/rails/security/advisories/GHSA-pgm4-439c-5jp6 x_refsource_CONFIRM
-
https://github.com/rails/rails/releases/tag/v8.1.2.1 x_refsource_MISC
Affected products
actionpack
- ==>= 8.1.0, < 8.1.2.1
Matching in nixpkgs
pkgs.rubyPackages.actionpack
None
pkgs.rubyPackages_3_1.actionpack
None
pkgs.rubyPackages_3_2.actionpack
None
pkgs.rubyPackages_3_3.actionpack
None
pkgs.rubyPackages_3_4.actionpack
None
pkgs.rubyPackages_4_0.actionpack
None
pkgs.perlPackages.HTTPHeadersActionPack
HTTP Action, Adventure and Excitement
pkgs.perl5Packages.HTTPHeadersActionPack
HTTP Action, Adventure and Excitement
pkgs.perl538Packages.HTTPHeadersActionPack
HTTP Action, Adventure and Excitement
pkgs.perl540Packages.HTTPHeadersActionPack
HTTP Action, Adventure and Excitement