PT-2024-7925 · Ruby On Rails+6 · Action Pack+6

Scyoon

·

Published

2024-10-15

·

Updated

2025-11-25

·

CVE-2024-47887

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Action Pack versions 4.0.0 through 6.1.7.8 Action Pack versions 7.0.0 through 7.0.8.4 Action Pack versions 7.1.0 through 7.1.4.0 Action Pack versions 7.2.0 through 7.2.1.0
Description The issue is related to a ReDoS vulnerability in Action Controller's HTTP Token authentication, which can cause header parsing to take an unexpected amount of time, possibly resulting in a DoS vulnerability. This can be exploited by a remote attacker, allowing them to cause a denial of service. For applications using HTTP Token authentication via authenticate or request with http token or similar, a carefully crafted header may cause the issue.
Recommendations For Action Pack versions 4.0.0 through 6.1.7.8, upgrade to version 6.1.7.9 or apply the relevant patch. For Action Pack versions 7.0.0 through 7.0.8.4, upgrade to version 7.0.8.5 or apply the relevant patch. For Action Pack versions 7.1.0 through 7.1.4.0, upgrade to version 7.1.4.1 or apply the relevant patch. For Action Pack versions 7.2.0 through 7.2.1.0, upgrade to version 7.2.1.1 or apply the relevant patch. As a temporary workaround, consider using Ruby 3.2 or newer, as it has mitigations for this problem.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3714
BDU:2024-09429
BIT-RAILS-2024-47887
CVE-2024-47887
DLA-4383-1
DSA-5881-1
GHSA-VFG9-R3FQ-JVX4
OESA-2024-2411
OPENSUSE-SU-2024:14472-1
OPENSUSE-SU-2024:14479-1
OPENSUSE-SU-2025:15110-1
OPENSUSE-SU-2025:15124-1
SUSE-SU-2024:3877-1
USN-7290-1

Affected Products

Alt Linux
Action Pack
Debian
Linuxmint
Red Os
Suse
Ubuntu