CVE-2024-26144: Possible Sensitive Session Information Leak in Active Storage

Published Feb 26, 2024
·
Updated

Possible Sensitive Session Information Leak in Active Storage

There is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak.

This vulnerability has been assigned the CVE identifier CVE-2024-26144.

Versions Affected: >= 5.2.0, < 7.1.0 Not affected: < 5.2.0, > 7.1.0 Fixed Versions: 7.0.8.1, 6.1.7.7

Impact ------ A proxy which chooses to caches this request can cause users to share sessions. This may include a user receiving an attacker's session or vice versa.

This was patched in 7.1.0 but not previously identified as a security vulnerability.

All users running an affected release should either upgrade or use one of the workarounds immediately.

Releases -------- The fixed releases are available at the normal locations.

Workarounds ----------- Upgrade to Rails 7.1.X, or configure caching proxies not to cache the Set-Cookie headers.

Credits -------

Thanks to tyage for reporting this!

Other sources

Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.

MITRE

There is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user’s session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak.

Refer; https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2024-26144.yml

Red Hat

Affected Software

6 affected componentsFixes available
redhat/rubygem-activestorage<7.0.8.1
7.0.8.1
redhat/rubygem-activestorage<6.1.7.7
6.1.7.7
rubyonrails Rails>=5.2.0<6.1.7.7
rubyonrails Rails>=7.0.0<7.1.0
rubygems/activestorage>=7.0.0<7.0.8.1
7.0.8.1
rubygems/activestorage>=5.2.0<6.1.7.7
6.1.7.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rubygems/activestorage to a version that resolves this vulnerability.

    Fixed in 7.0.8.1
  2. Upgrade

    Upgrade rubygems/activestorage to a version that resolves this vulnerability.

    Fixed in 6.1.7.7
  3. Upgrade

    Upgrade redhat/rubygem-activestorage to a version that resolves this vulnerability.

    Fixed in 7.0.8.1
  4. Upgrade

    Upgrade redhat/rubygem-activestorage to a version that resolves this vulnerability.

    Fixed in 6.1.7.7
  5. Upgrade

    Upgrade Rails Active Storage to a version that resolves this vulnerability.

    Fixed in 7.0.8.1
  6. Upgrade

    Upgrade Rails Active Storage to a version that resolves this vulnerability.

    Fixed in 6.1.7.7
  7. Compensating control

    Upgrade Rails to 7.1.X as remediation, or configure caching proxies not to cache the Set-Cookie header when serving Active Storage blobs (this issue can occur if proxies cache Set-Cookie, which Active Storage sends by default along with the user’s session cookie and also sets Cache-Control to public).

Event History

Feb 26, 2024
Data Sourced
via Red Hat·02:23 PM
DescriptionSeverityAffected Software
Feb 27, 2024
CVE Published
via MITRE·03:44 PM
Data Sourced
via MITRE·03:44 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:41 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-26144?

CVE-2024-26144 is classified as a possible information leak vulnerability that can expose sensitive session information.

2

How do I fix CVE-2024-26144?

To fix CVE-2024-26144, upgrade Active Storage to version 7.0.8.1 or 6.1.7.7 or higher.

3

Which versions of Active Storage are affected by CVE-2024-26144?

Versions of Active Storage from 5.2.0 to 7.0.8.0 and from 6.1.0 to 6.1.7.6 are affected by CVE-2024-26144.

4

What platforms are impacted by CVE-2024-26144?

CVE-2024-26144 impacts both the rubygems and redhat packages of Active Storage.

5

Is a workaround available for CVE-2024-26144?

There is no specific workaround for CVE-2024-26144; upgrading to the fixed versions is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203