CVE-2024-26142
Last modified
CVE-2024-26142 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. EPSS estimates a 1.50% chance of exploitation in the next 30 days.
Description
Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rubyonrails | Rails | >= 7.1.0, < 7.1.3.1 |
References
- https://security.netapp.com/advisory/ntap-20240503-0003/Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240503-0003/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-26142?
How severe is CVE-2024-26142?
How do I fix CVE-2024-26142?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-26136kedi ElectronCord is a bot management tool for Discord. Comm…7.5
- CVE-2024-26138The XWiki licensor application, which manages and enforce ap…5.3
- CVE-2024-26139OpenCTI is an open source platform allowing organizations to…8.1
- CVE-2024-2614Memory safety bugs present in Firefox 123, Firefox ESR 115.8…8.8
- CVE-2024-26140com.yetanalytics/lrs is the Yet Analytics Core LRS Library. …6.1
- CVE-2024-26141Rack is a modular Ruby web server interface. Carefully craft…7.5
- CVE-2024-26143Rails is a web-application framework. There is a possible XS…6.1
- CVE-2024-26144Rails is a web-application framework. Starting with version …5.3
- CVE-2024-26145Discourse Calendar adds the ability to create a dynamic cale…4.3
- CVE-2024-26146Rack is a modular Ruby web server interface. Carefully craft…7.5
- CVE-2024-26147Helm is a package manager for Charts for Kubernetes. Version…7.5
- CVE-2024-26148Querybook is a user interface for querying big data. Prior t…6.1
Are you affected by CVE-2024-26142?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
