CVE-2022-23633
Summary
| CVE | CVE-2022-23633 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-11 21:15:00 UTC |
| Updated | 2024-01-19 16:15:00 UTC |
| Description | Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 3093-1] rails security update |
MLIST |
lists.debian.org |
|
| oss-security - [CVE-2022-23633] Possible exposure of information vulnerability in
Action Pack |
MLIST |
www.openwall.com |
|
| Possible exposure of information vulnerability in Action Pack · Advisory · rails/rails · GitHub |
CONFIRM |
github.com |
|
| Debian -- Security Information -- DSA-5372-1 rails |
DEBIAN |
www.debian.org |
|
| CVE-2022-23633 Ruby on Rails Vulnerability in NetApp Products | NetApp Product Security |
|
security.netapp.com |
|
| Fix reloader to work with new Executor signature · rails/rails@f9a2ad0 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180989 Debian Security Update for rails (DLA 3093-1)
- 181676 Debian Security Update for rails (DSA 5372-1)
- 184142 Debian Security Update for rails (CVE-2022-23633)
- 240566 Red Hat Update for Satellite 6.11 Release (RHSA-2022:5498)
- 753313 SUSE Enterprise Linux Security Update for rubygem-actionpack-5_1, rubygem-activesupport-5_1 (SUSE-SU-2022:2108-1)
- 960505 Rocky Linux Security Update for Satellite (RLSA-2022:5498)