First published: Wed May 05 2021(Updated: )
A flaw was found in RubyGem Actionpack which is framework for handling and responding to web requests in Rails. A possible DoS vulnerability was found in the Token Authentication logic in Action Controller.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/tfm-rubygem-rails | <0:6.0.3.7-1.el7 | 0:6.0.3.7-1.el7 |
rubygems/actionpack | >=4.0.0<=5.2.4.5 | 5.2.4.6 |
rubygems/actionpack | >=5.2.5<5.2.6 | 5.2.6 |
rubygems/actionpack | >=6.1.0<=6.1.3.1 | 6.1.3.2 |
rubygems/actionpack | >=6.0.0<=6.0.3.6 | 6.0.3.7 |
Rubyonrails Rails | <5.2.4.6 | |
Rubyonrails Rails | >=5.2.5<5.2.6 | |
Rubyonrails Rails | >=6.0.0<6.0.3.7 | |
Rubyonrails Rails | >=6.1.0<6.1.3.2 | |
debian/rails | 2:5.2.2.1+dfsg-1+deb10u3 2:5.2.2.1+dfsg-1+deb10u5 2:6.0.3.7+dfsg-2+deb11u2 2:6.1.7.3+dfsg-1 2:6.1.7.3+dfsg-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this flaw is CVE-2021-22904.
The severity of CVE-2021-22904 is high (7.5).
Versions >= 4.0.0 of Actionpack are affected by CVE-2021-22904.
You can fix CVE-2021-22904 by updating to one of the fixed versions: 6.1.3.2, 6.0.3.7, 5.2.4.6, or 5.2.6.