PT-2024-10400 · Unknown+3 · Action Pack+3

Jhawthorn

+1

·

Published

2024-12-10

·

Updated

2026-03-16

·

CVE-2024-54133

CVSS v4.0

2.3

Low

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Action Pack versions 5.2.0 through 7.0.8.6 Action Pack versions 7.0.8.7 through 7.1.5.0 Action Pack versions 7.1.5.1 through 7.2.2.0 Action Pack versions 7.2.2.1 through 8.0.0.0
Description The issue is related to the content security policy helper in Action Pack, which may allow an attacker to conduct Cross Site Scripting (XSS) attacks by injecting new directives into the Content-Security-Policy (CSP) headers. This could lead to a bypass of the CSP and its protection against XSS and other attacks. Applications that set CSP headers dynamically from untrusted user input may be vulnerable.
Recommendations For Action Pack versions 5.2.0 through 7.0.8.6, update to version 7.0.8.7 or later. For Action Pack versions 7.0.8.7 through 7.1.5.0, update to version 7.1.5.1 or later. For Action Pack versions 7.1.5.1 through 7.2.2.0, update to version 7.2.2.1 or later. For Action Pack versions 7.2.2.1 through 8.0.0.0, update to version 8.0.0.1 or later. As a temporary workaround, applications can avoid setting CSP headers dynamically from untrusted input, or can validate/sanitize that input.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3714
BDU:2025-00917
BIT-RAILS-2024-54133
CVE-2024-54133
DLA-4383-1
DSA-5881-1
GHSA-VFM5-RMRH-J26V
OPENSUSE-SU-2025:14668-1
OPENSUSE-SU-2025:14669-1
OPENSUSE-SU-2025:14670-1
OPENSUSE-SU-2025:14671-1
OPENSUSE-SU-2025:14672-1
OPENSUSE-SU-2025:14673-1
OPENSUSE-SU-2025:14674-1
OPENSUSE-SU-2025:14675-1
OPENSUSE-SU-2025:14676-1
OPENSUSE-SU-2025:14677-1
OPENSUSE-SU-2025:14678-1
OPENSUSE-SU-2025:14679-1
OPENSUSE-SU-2025:14680-1
OPENSUSE-SU-2026:10335-1
OPENSUSE-SU-2026:10336-1
OPENSUSE-SU-2026:10337-1
OPENSUSE-SU-2026:10338-1
OPENSUSE-SU-2026:10339-1
OPENSUSE-SU-2026:10340-1
OPENSUSE-SU-2026:10341-1
OPENSUSE-SU-2026:10342-1
OPENSUSE-SU-2026:10343-1
OPENSUSE-SU-2026:10344-1
OPENSUSE-SU-2026:10345-1
OPENSUSE-SU-2026:10360-1
OPENSUSE-SU-2026:10362-1

Affected Products

Alt Linux
Action Pack
Debian
Red Os