CVE-2022-22577: XSS
A flaw was found in rubygem-actionpack where CSP headers were sent with responses that Rails considered "HTML" responses. This flaw allows an attacker to leave API requests without CSP headers and perform a Cross-site scripting attack.
Other sources
An XSS Vulnerability in Action Pack >= 5.2.0 and < 5.2.0 that could allow an attacker to bypass CSP for non HTML like responses.
There is a possible XSS vulnerability in Rails / Action Pack.
References:
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2022-22577.yml
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/railsto a version that resolves this vulnerability.Fixed in 2:5.2.2.1+dfsg-1+deb10u5Fixed in 2:6.0.3.7+dfsg-2+deb11u2Fixed in 2:6.1.7.3+dfsg-1Fixed in 2:6.1.7.3+dfsg-2 - Upgrade
Upgrade
redhat/rubygem-actionpackto a version that resolves this vulnerability.Fixed in 0:6.1.7-1.el8 - Upgrade
Upgrade
redhat/rubygem-actionpackto a version that resolves this vulnerability.Fixed in 7.0.2.4 - Upgrade
Upgrade
redhat/rubygem-actionpackto a version that resolves this vulnerability.Fixed in 6.1.5.1 - Upgrade
Upgrade
redhat/rubygem-actionpackto a version that resolves this vulnerability.Fixed in 6.0.4.8 - Upgrade
Upgrade
redhat/rubygem-actionpackto a version that resolves this vulnerability.Fixed in 5.2.7.1
Event History
Frequently Asked Questions
What is CVE-2022-22577?
CVE-2022-22577 is an XSS vulnerability in Action Pack versions greater than or equal to 5.2.0 and less than 5.2.0, which could allow an attacker to bypass CSP headers and perform a cross-site scripting attack.
How severe is CVE-2022-22577?
CVE-2022-22577 has a severity level of 7.5 (high).
Which software versions are affected by CVE-2022-22577?
Action Pack versions 5.2.0 to 5.2.7.1, 6.0.0 to 6.0.4.8, 6.1.0 to 6.1.5.1, and 7.0.0 to 7.0.2.4 are affected by CVE-2022-22577.
How can I fix CVE-2022-22577?
To fix CVE-2022-22577, upgrade to Action Pack version 5.2.7.1, 6.0.4.8, 6.1.5.1, or 7.0.2.4, depending on your current version.
Where can I find more information about CVE-2022-22577?
You can find more information about CVE-2022-22577 in the Ruby Advisory Database, Red Hat Bugzilla, and Red Hat Errata.