PT-2024-7931 · Ruby On Rails+7 · Action Mailer+7

Yuki_Osaki

·

Published

2024-10-15

·

Updated

2025-11-25

·

CVE-2024-47889

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Action Mailer versions 3.0.0 through 6.1.7.8 Action Mailer versions 7.0.0 through 7.0.8.4 Action Mailer versions 7.1.0 through 7.1.4.0 Action Mailer versions 7.2.0 through 7.2.1.0
Description The issue is related to the block format helper in Action Mailer, which has a possible ReDoS vulnerability. This vulnerability can cause the block format helper to take an unexpected amount of time when processing carefully crafted text, possibly resulting in a DoS vulnerability. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.
Recommendations For Action Mailer versions 3.0.0 through 6.1.7.8, upgrade to version 6.1.7.9 or apply the relevant patch immediately. For Action Mailer versions 7.0.0 through 7.0.8.4, upgrade to version 7.0.8.5 or apply the relevant patch immediately. For Action Mailer versions 7.1.0 through 7.1.4.0, upgrade to version 7.1.4.1 or apply the relevant patch immediately. For Action Mailer versions 7.2.0 through 7.2.1.0, upgrade to version 7.2.1.1 or apply the relevant patch immediately. As a temporary workaround, users can avoid calling the block format helper. Users can also upgrade to Ruby 3.2, which has mitigations for this problem.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3714
BDU:2024-09435
BIT-RAILS-2024-47889
CVE-2024-47889
DLA-4383-1
DSA-5881-1
GHSA-H47H-MWP9-C6Q6
OESA-2024-2383
OPENSUSE-SU-2024:14471-1
OPENSUSE-SU-2024:14479-1
OPENSUSE-SU-2025:15109-1
OPENSUSE-SU-2025:15124-1
SUSE-SU-2024:3878-1
SUSE-SU-2024_3878-1
USN-7290-1

Affected Products

Alt Linux
Action Mailer
Debian
Linuxmint
Red Os
Ruby
Suse
Ubuntu