Rails是美国Rails团队的一套基于Ruby语言的开源Web应用框架。 Rails 7.0.0及之前版本存在安全漏洞,该漏洞源于在Action Controller中使用翻译助手时存在跨站脚本(XSS)漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-26142 | 7.5 HIGH | Rails possible ReDoS vulnerability in Accept header parsing in Action Dispatch |
| CVE-2024-26144 | 5.3 MEDIUM | Possible Sensitive Session Information Leak in Active Storage |
No comments yet