CVE-2024-26144

CVSS V2 None CVSS V3 None
Description
Rails is a web-application framework. Starting with version 5.2.0, there is a possible sensitive session information leak in Active Storage. By default, Active Storage sends a Set-Cookie header along with the user's session cookie when serving blobs. It also sets Cache-Control to public. Certain proxies may cache the Set-Cookie, leading to an information leak. The vulnerability is fixed in 7.0.8.1 and 6.1.7.7.
Overview
  • CVE ID
  • CVE-2024-26144
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-27T15:44:04.166Z
  • Last Modified Date
  • 2024-02-27T15:44:04.166Z
History
Created Old Value New Value Data Type Notes
2024-06-26 00:25:04 Added to TrackCVE