VDB
KO
MEDIUM 6.1

GHSA-mm33-5vfq-3mm3

Cross-site Scripting Vulnerability in Action Pack

Details

There is a possible XSS vulnerability in Rails / Action Pack. This vulnerability has been assigned the CVE identifier CVE-2022-22577.

Versions Affected: >= 5.2.0 Not affected: < 5.2.0 Fixed Versions: 7.0.2.4, 6.1.5.1, 6.0.4.8, 5.2.7.1

## Impact

CSP headers were only sent along with responses that Rails considered as "HTML" responses. This left API requests without CSP headers, which could possibly expose users to XSS attacks.

## Releases

The FIXED releases are available at the normal locations.

## Workarounds

Set a CSP for your API responses manually.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / actionpack
Introduced in: 5.2.0 Fixed in: 5.2.7.1
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 6.0.0 Fixed in: 6.0.4.8
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 6.1.0 Fixed in: 6.1.5.1
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 7.0.0 Fixed in: 7.0.2.4
Fix bundle update actionpack

References