Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A…
中危 CVSS 6.1
摘要
Action Pack is a Rubygem for building web applications on the Rails framework. In versions on the 8.1 branch prior to 8.1.2.1, the debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development. Version 8.1.2.1 contains a patch.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/rails/rails/commit/6752711c8c31d79ba50d13af6a6698a3b85415e0 Patch
- https://github.com/rails/rails/releases/tag/v8.1.2.1 Release Notes
- https://github.com/rails/rails/security/advisories/GHSA-pgm4-439c-5jp6 Vendor Advisory
时间线
- nvd_ingest NVD