VDB
Sign up
MEDIUM6.1

GHSA-prjp-h48f-jgf6

ActionText ContentAttachment can Contain Unsanitized HTML

Quick fix

GHSA-prjp-h48f-jgf6 — actiontext: upgrade to the fixed version with the command below.

bundle update actiontext

Details

Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML.

This has been assigned the CVE identifier CVE-2024-32464.

Versions Affected: >= 7.1.0 Not affected: < 7.1.0 Fixed Versions: 7.1.3.4

Impact ------ This could lead to a potential cross site scripting issue within the Trix editor.

Releases -------- The fixed releases are available at the normal locations.

Workarounds ----------- N/A

Patches ------- To aid users who aren't able to upgrade immediately we have provided patches for the supported release series in accordance with our [maintenance policy](https://guides.rubyonrails.org/maintenance_policy.html#security-issues) regarding security issues. They are in git-am format and consist of a single changeset.

* action_text_content_attachment_xss_7_1_stable.patch - Patch for 7.1 series

Credits -------

Thank you [ooooooo_q](https://hackerone.com/ooooooo_q) for reporting this!

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/actiontext
Introduced in: 7.1.0Fixed in: 7.1.3.4
Fixbundle update actiontext
RubyGems/actiontext
Introduced in: 7.2.0.beta1Fixed in: 7.2.0.beta2
Fixbundle update actiontext

References