rubygem-actionpack: possible XSS vulnerability in Action Pack in development mode
Published Jan 6, 2021
7.7
HIGHCVSS 3.1
EPSS 66.99%
Description
In actionpack gem >= 6.0.0, a possible XSS vulnerability exists when an application is running in development mode allowing an attacker to send or embed (in another page) a specially crafted URL which can allow the attacker to execute JavaScript in the context of the local application. This vulnerability is in the Actionable Exceptions middleware.
Affected products
No data.
- ≥ 6.0.0 · < 6.0.3.4
No data.
CloudForms Management Engine 5
cfme-amazon-smartstate
Not affected
CloudForms Management Engine 5
cfme-gemset
Not affected
Red Hat Satellite 6
tfm-ror52-rubygem-rails
Not affected
Red Hat Satellite 6
tfm-rubygem-actionpack
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | cfme-amazon-smartstate | Not affected | n/a |
| CloudForms Management Engine 5 | cfme-gemset | Not affected | n/a |
| Red Hat Satellite 6 | tfm-ror52-rubygem-rails | Not affected | n/a |
| Red Hat Satellite 6 | tfm-rubygem-actionpack | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat products ships rubygem-actionpack, however, those are supposed to be run in production mode. This issue only impacts development mode, therefore mentioned products are not affected by this flaw.
References (9)
- https://access.redhat.com/security/cve/CVE-2020-8264 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1886554 Issue Tracking
- https://github.com/advisories/GHSA-35mm-cc6r-8fjp Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2020-8264.yml
- https://groups.google.com/g/rubyonrails-security/c/yQzUVfv42jk
- https://groups.google.com/g/rubyonrails-security/c/yQzUVfv42jk/m/oJWw-xhNAQAJ x_refsource_MISCMailing ListThird Party Advisory
- https://hackerone.com/reports/904059 x_refsource_MISCExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8264
- https://www.cve.org/CVERecord?id=CVE-2020-8264
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8264 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1886554 | Issue Tracking | |
| https://github.com/advisories/GHSA-35mm-cc6r-8fjp | Advisory | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2020-8264.yml | ||
| https://groups.google.com/g/rubyonrails-security/c/yQzUVfv42jk | ||
| https://groups.google.com/g/rubyonrails-security/c/yQzUVfv42jk/m/oJWw-xhNAQAJ | x_refsource_MISCMailing ListThird Party Advisory | |
| https://hackerone.com/reports/904059 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8264 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-8264 |
Change history (0)
No recorded changes yet.