Instances of ActionText::Attachable::ContentAttachment included within a rich_text_area tag could potentially contain unsanitized HTML.
This has been assigned the CVE identifier CVE-2024-32464.
Versions Affected: >= 7.1.0
Not affected: < 7.1.0
Fixed Versions: 7.1.3.4
This could lead to a potential cross site scripting issue within the Trix editor.
The fixed releases are available at the normal locations.
N/A
To aid users who aren't able to upgrade immediately we have provided patches for the supported release series in accordance with our maintenance policy regarding security issues. They are in git-am format and consist of a single changeset.
Thank you ooooooo_q for reporting this!
| Score | Percentile |
|---|---|
| 0.28% | 50.95% |
| Base score | Version | Severity | Vector |
|---|---|---|---|
| 6.1 | 3.1 | — |
|
| 5.1 | 4.0 | — |
|
| Type | Value |
|---|---|
| GHSA | GHSA-prjp-h48f-jgf6 ↗ |
| CVE | CVE-2024-32464 ↗ |
| CWE id | Name |
|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Vulnerable version ranges and first patched releases as published by GitHub.
| Ecosystem | Package | Vulnerable range | First patched | Vulnerable functions |
|---|---|---|---|---|
| rubygems | actiontext | >= 7.1.0, < 7.1.3.4 | 7.1.3.4 | — |
| rubygems | actiontext | = 7.2.0.beta1 | 7.2.0.beta2 | — |