VDB
EN
HIGH 7.4

GHSA-wh98-p28r-vrc9

Exposure of information in Action Pack

상세

### Impact

Under certain circumstances response bodies will not be closed, for example a [bug in a webserver](https://github.com/puma/puma/pull/2812) or a bug in a Rack middleware. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests, especially when interacting with `ActiveSupport::CurrentAttributes`.

Upgrading to the FIXED versions of Rails will ensure mitigation of this issue even in the context of a buggy webserver or middleware implementation.

### Patches

This has been fixed in Rails 7.0.2.2, 6.1.4.6, 6.0.4.6, and 5.2.6.2.

### Workarounds

Upgrading is highly recommended, but to work around this problem the following middleware can be used:

```ruby class GuardedExecutor < ActionDispatch::Executor def call(env) ensure_completed! super end

private

def ensure_completed! @executor.new.complete! if @executor.active? end end

# Ensure the guard is inserted before ActionDispatch::Executor Rails.application.configure do config.middleware.swap ActionDispatch::Executor, GuardedExecutor, executor end ```

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

RubyGems / actionpack
최초 영향 버전: 5.0.0.0 수정 버전: 5.2.6.2
수정 bundle update actionpack
RubyGems / actionpack
최초 영향 버전: 6.0.0.0 수정 버전: 6.0.4.6
수정 bundle update actionpack
RubyGems / actionpack
최초 영향 버전: 6.1.0.0 수정 버전: 6.1.4.6
수정 bundle update actionpack
RubyGems / actionpack
최초 영향 버전: 7.0.0.0 수정 버전: 7.0.2.2
수정 bundle update actionpack

참고