CVE-2024-26144: Possible Sensitive Session Information Leak in Active Storage
Possible Sensitive Session Information Leak in Active Storage
There is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak.
This vulnerability has been assigned the CVE identifier CVE-2024-26144.
Versions Affected: >= 5.2.0, < 7.1.0 Not affected: < 5.2.0, > 7.1.0 Fixed Versions: 7.0.8.1, 6.1.7.7
Impact ------ A proxy which chooses to caches this request can cause users to share sessions. This may include a user receiving an attacker's session or vice versa.
This was patched in 7.1.0 but not previously identified as a security vulnerability.
All users running an affected release should either upgrade or use one of the workarounds immediately.
Releases -------- The fixed releases are available at the normal locations.
Workarounds ----------- Upgrade to Rails 7.1.X, or configure caching proxies not to cache the Set-Cookie headers.
Credits -------
Thanks to tyage for reporting this!
Other sources
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.
— MITRE
There is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user’s session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak.
Refer; https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2024-26144.yml
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rubygems/activestorageto a version that resolves this vulnerability.Fixed in 7.0.8.1 - Upgrade
Upgrade
rubygems/activestorageto a version that resolves this vulnerability.Fixed in 6.1.7.7 - Upgrade
Upgrade
redhat/rubygem-activestorageto a version that resolves this vulnerability.Fixed in 7.0.8.1 - Upgrade
Upgrade
redhat/rubygem-activestorageto a version that resolves this vulnerability.Fixed in 6.1.7.7 - Upgrade
Upgrade
Rails Active Storageto a version that resolves this vulnerability.Fixed in 7.0.8.1 - Upgrade
Upgrade
Rails Active Storageto a version that resolves this vulnerability.Fixed in 6.1.7.7 - Compensating control
Upgrade Rails to 7.1.X as remediation, or configure caching proxies not to cache the Set-Cookie header when serving Active Storage blobs (this issue can occur if proxies cache Set-Cookie, which Active Storage sends by default along with the user’s session cookie and also sets Cache-Control to public).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26144?
CVE-2024-26144 is classified as a possible information leak vulnerability that can expose sensitive session information.
How do I fix CVE-2024-26144?
To fix CVE-2024-26144, upgrade Active Storage to version 7.0.8.1 or 6.1.7.7 or higher.
Which versions of Active Storage are affected by CVE-2024-26144?
Versions of Active Storage from 5.2.0 to 7.0.8.0 and from 6.1.0 to 6.1.7.6 are affected by CVE-2024-26144.
What platforms are impacted by CVE-2024-26144?
CVE-2024-26144 impacts both the rubygems and redhat packages of Active Storage.
Is a workaround available for CVE-2024-26144?
There is no specific workaround for CVE-2024-26144; upgrading to the fixed versions is recommended.