GHSA-prjp-h48f-jgf6
ActionText ContentAttachment can Contain Unsanitized HTML
Quick fix
GHSA-prjp-h48f-jgf6 — actiontext: upgrade to the fixed version with the command below.
bundle update actiontextDetails
Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML.
This has been assigned the CVE identifier CVE-2024-32464.
Versions Affected: >= 7.1.0 Not affected: < 7.1.0 Fixed Versions: 7.1.3.4
Impact ------ This could lead to a potential cross site scripting issue within the Trix editor.
Releases -------- The fixed releases are available at the normal locations.
Workarounds ----------- N/A
Patches ------- To aid users who aren't able to upgrade immediately we have provided patches for the supported release series in accordance with our [maintenance policy](https://guides.rubyonrails.org/maintenance_policy.html#security-issues) regarding security issues. They are in git-am format and consist of a single changeset.
* action_text_content_attachment_xss_7_1_stable.patch - Patch for 7.1 series
Credits -------
Thank you [ooooooo_q](https://hackerone.com/ooooooo_q) for reporting this!
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rails/rails/security/advisories/GHSA-prjp-h48f-jgf6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-32464[ADVISORY]
- https://github.com/rails/rails/commit/e215bf3360e6dfe1497c1503a495e384ed6b0995[WEB]
- https://github.com/rails/rails[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actiontext/CVE-2024-32464.yml[WEB]