PT-2024-7933 · Unknown+6 · Actiontext+6

Oooooo_Q

·

Published

2024-10-15

·

Updated

2025-11-25

·

CVE-2024-47888

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions Action Text versions 6.0.0 through 6.1.7.8 Action Text versions 7.0.0 through 7.0.8.4 Action Text versions 7.1.0 through 7.1.4.0 Action Text versions 7.2.0 through 7.2.1.0
Description The issue is related to the plain text for blockquote node helper in Action Text, which can cause a denial of service due to a possible ReDoS vulnerability. Carefully crafted text can make the plain text for blockquote node helper take an unexpected amount of time. This problem can be mitigated in Ruby 3.2 or newer, so Rails applications using Ruby 3.2 or newer are unaffected.
Recommendations For Action Text versions 6.0.0 through 6.1.7.8, upgrade to version 6.1.7.9 or apply the relevant patch. For Action Text versions 7.0.0 through 7.0.8.4, upgrade to version 7.0.8.5 or apply the relevant patch. For Action Text versions 7.1.0 through 7.1.4.0, upgrade to version 7.1.4.1 or apply the relevant patch. For Action Text versions 7.2.0 through 7.2.1.0, upgrade to version 7.2.1.1 or apply the relevant patch. As a temporary workaround, users can avoid calling plain text for blockquote node or upgrade to Ruby 3.2.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3714
BDU:2024-09437
BIT-RAILS-2024-47888
CVE-2024-47888
DLA-4383-1
DSA-5881-1
GHSA-WWHV-WXV9-RPGW
OPENSUSE-SU-2024:14473-1
OPENSUSE-SU-2024:14479-1
OPENSUSE-SU-2025:15111-1
OPENSUSE-SU-2025:15124-1
USN-7290-1

Affected Products

Alt Linux
Actiontext
Debian
Linuxmint
Red Os
Ruby
Ubuntu