REDHAT-BUG-2319036: Low severity Ruby on Rails Action Dispatch vulnerability
There is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dispatch. This vulnerability has been assigned the CVE identifier CVE-2024-41128.
Impact ------
Carefully crafted query parameters can cause query parameter filtering to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade or apply the relevant patch immediately.
Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected. Rails 8.0.0.beta1 depends on Ruby 3.2 or greater so is unaffected.
Releases -------- The fixed releases are available at the normal locations.
Workarounds ----------- Users on Ruby 3.2 are unaffected by this issue.
Credits -------
Thanks to scyoon for the report and patches!
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2319036?
The severity of REDHAT-BUG-2319036 is classified as high due to its potential for ReDoS attacks.
How do I fix REDHAT-BUG-2319036?
To fix REDHAT-BUG-2319036, upgrade Ruby on Rails Action Dispatch to a version above 8.0.0.beta1.
What kind of attacks can exploit REDHAT-BUG-2319036?
REDHAT-BUG-2319036 can be exploited through ReDoS attacks, which can potentially lead to denial of service.
Which versions of Ruby on Rails Action Dispatch are affected by REDHAT-BUG-2319036?
Versions of Ruby on Rails Action Dispatch up to 8.0.0.beta1 are affected by REDHAT-BUG-2319036.
Is there a known workaround for REDHAT-BUG-2319036?
Currently, the recommended approach for REDHAT-BUG-2319036 is to apply the software update, as a specific workaround is not documented.