CVE-2024-26144

EUVD-2024-0573
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
GitHub_MCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
rubyonrailsrails
5.2.0 ≤
𝑥
< 6.1.7.7
rubyonrailsrails
7.0.0 ≤
𝑥
< 7.1.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rails
bookworm
2:6.1.7.10+dfsg-1~deb12u1
fixed
bookworm (security)
2:6.1.7.10+dfsg-1~deb12u2
fixed
bullseye
2:6.0.3.7+dfsg-2+deb11u2
not-affected
bullseye (security)
2:6.0.3.7+dfsg-2+deb11u4
fixed
forky
2:7.2.2.2+dfsg-2
fixed
sid
2:7.2.2.2+dfsg-2
fixed
trixie
2:7.2.2.1+dfsg-7
fixed
trixie (security)
2:7.2.2.2+dfsg-2~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rails
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
mantic
ignored
noble
needs-triage
oracular
ignored
plucky
needs-triage
questing
needs-triage
trusty
ignored
xenial
needs-triage
ruby-rails-3.2
bionic
dne
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
ignored
xenial
dne
ruby-actionpack-3.2
bionic
dne
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
ignored
xenial
dne
ruby-activesupport-3.2
bionic
dne
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
ignored
xenial
dne
ruby-activerecord-3.2
bionic
dne
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
ignored
xenial
dne
ruby-activemodel-3.2
bionic
dne
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
ignored
xenial
dne
rails-4.0
bionic
dne
focal
dne
jammy
dne
mantic
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
ignored
xenial
dne