CVE-2024-26143: Rails Possible XSS Vulnerability in Action Controller
Possible XSS Vulnerability in Action Controller
There is a possible XSS vulnerability when using the translation helpers (translate, t, etc) in Action Controller. This vulnerability has been assigned the CVE identifier CVE-2024-26143.
Versions Affected: >= 7.0.0. Not affected: < 7.0.0 Fixed Versions: 7.1.3.1, 7.0.8.1
Impact ------ Applications using translation methods like translate, or t on a controller, with a key ending in "html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability.
For example, impacted code will look something like this:
ruby class ArticlesController < ApplicationController def show @message = t("messagehtml", default: untrustedinput) # The show template displays the contents of @message end end
To reiterate the pre-conditions, applications must:
Use a translation function from a controller (i.e. not I18n.t, or t from a view) Use a key that ends in html Use a default value where the default value is untrusted and unescaped input Send the text to the victim (whether that's part of a template, or a render call)
All users running an affected release should either upgrade or use one of the workarounds immediately.
Releases -------- The fixed releases are available at the normal locations.
Workarounds ----------- There are no feasible workarounds for this issue.
Patches ------- To aid users who aren't able to upgrade immediately we have provided patches for the two supported release series. They are in git-am format and consist of a single changeset.
7-0-translate-xss.patch - Patch for 7.0 series 7-1-translate-xss.patch - Patch for 7.1 series
Credits -------
Thanks to oooooooq for the patch and fix!
Other sources
Rails is a web-application framework. There is a possible XSS vulnerability when using the translation helpers in Action Controller. Applications using translation methods like translate, or t on a controller, with a key ending in "html", a :default key which contains untrusted user input, and the resulting string is used in a view, may be susceptible to an XSS vulnerability. The vulnerability is fixed in 7.1.3.1 and 7.0.8.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/railsto a version that resolves this vulnerability.Fixed in 7.1.3.1 - Upgrade
Upgrade
rubygems/railsto a version that resolves this vulnerability.Fixed in 7.0.8.1 - Upgrade
Upgrade
rubygems/actionpackto a version that resolves this vulnerability.Fixed in 7.1.3.1 - Upgrade
Upgrade
rubygems/actionpackto a version that resolves this vulnerability.Fixed in 7.0.8.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.1.3.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.0.8.1
Event History
Frequently Asked Questions
What is the CVSS score of CVE-2024-26143?
The CVSS score for CVE-2024-26143 is not explicitly stated in the available resources.
What versions are affected by CVE-2024-26143?
CVE-2024-26143 affects versions of Action Controller that are 7.0.0 and above.
How can I mitigate CVE-2024-26143?
To mitigate CVE-2024-26143, upgrade to Action Pack version 7.1.3.1 or 7.0.8.1.
Is CVE-2024-26143 a risk for my Rails application?
Yes, CVE-2024-26143 poses a potential XSS risk for applications using vulnerable versions of Action Controller.
What are the consequences of exploiting CVE-2024-26143?
Exploiting CVE-2024-26143 could allow an attacker to execute arbitrary JavaScript code in the context of a user's browser.