Rails是美国Rails团队的一套基于Ruby语言的开源Web应用框架。 Rails 7.1.0至7.1.3.1之前版本存在安全漏洞,该漏洞源于Action Dispatch的Accept标头解析例程中存在正则表达式拒绝服务(ReDoS)漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2024-26143 | 6.1 MEDIUM | Rails Possible XSS Vulnerability in Action Controller |
| CVE-2024-26144 | 5.3 MEDIUM | Possible Sensitive Session Information Leak in Active Storage |
No comments yet