CVE-2024-28103
04.06.2024, 20:15
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.Enginsight
Vendor | Product | Version |
---|---|---|
rubyonrails | rails | 6.1.0 ≤ 𝑥 < 6.1.7.8 |
rubyonrails | rails | 7.0.0 ≤ 𝑥 < 7.0.8.4 |
rubyonrails | rails | 7.1.0 ≤ 𝑥 < 7.1.3.4 |
rubyonrails | rails | 7.2.0:beta1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References