CVE-2024-41128
Last modified
CVE-2024-41128 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale. Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dispatch. EPSS estimates a 1.10% chance of exploitation in the next 30 days.
Description
Action Pack is a framework for handling and responding to web requests. Starting in version 3.1.0 and prior to versions 6.1.7.9, 7.0.8.5, 7.1.4.1, and 7.2.1.1, there is a possible ReDoS vulnerability in the query parameter filtering routines of Action Dispatch. Carefully crafted query parameters can cause query parameter filtering to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release should either upgrade to version 6.1.7.9, 7.0.8.5, 7.1.4.1, or 7.2.1.1 or apply the relevant patch immediately. One may use Ruby 3.2 as a workaround. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected. Rails 8.0.0.beta1 depends on Ruby 3.2 or greater so is unaffected.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-41128?
How severe is CVE-2024-41128?
How do I fix CVE-2024-41128?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-41122Woodpecker is a simple yet powerful CI/CD engine with great …8.8
- CVE-2024-41123REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2…7.5
- CVE-2024-41124Puncia is the Official CLI utility for Subdomain Center & Ex…6.3
- CVE-2024-41125Contiki-NG is an open-source, cross-platform operating syste…9.6
- CVE-2024-41126Contiki-NG is an open-source, cross-platform operating syste…9.6
- CVE-2024-41127Monkeytype is a minimalistic and customizable typing test. M…9.6
- CVE-2024-41129The ops library is a Python framework for developing and tes…4.4
- CVE-2024-4113A vulnerability classified as critical was found in Tenda TX…8.8
- CVE-2024-41130llama.cpp provides LLM inference in C/C++. Prior to b3427, l…6.5
- CVE-2024-41131ImageSharp is a 2D graphics API. An Out-of-bounds Write vuln…7.5
- CVE-2024-41132ImageSharp is a 2D graphics API. A vulnerability discovered …7.5
- CVE-2024-41133A vulnerability exists in the HPE Aruba Networking EdgeConne…7.2
Are you affected by CVE-2024-41128?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
