Bug 2266388 (CVE-2024-26143)

Summary: CVE-2024-26143 rubygem-actionpack: Possible XSS on translation helpers
Product: [Other] Security Response Reporter: Marco Benatto <mbenatto>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: akostadi, amasferr, bbuckingham, bcourt, cbartlet, chazlett, dmayorov, ehelms, jlledo, jsherril, lzap, mhulan, mkudlej, mmakovy, nmoumoul, orabin, pcreech, rchan, tjochec
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: rubygem-actionpack 7.0.8.1, rubygem-actionpack 7.1.3.1 Doc Type: ---
Doc Text:
A vulnerability was found in actionpack ruby gem. Applications using the `translate` method may be susceptible to a cross-site scripting (XSS) attack.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2266389, 2266390, 2266391, 2266392, 2266393, 2266394, 2266395    
Bug Blocks: 2266322    

Description Marco Benatto 2024-02-27 18:18:06 UTC
There is a possible XSS vulnerability when using the translation helpers (`translate`, `t`, etc) in Action Controller. This vulnerability has been
assigned the CVE identifier CVE-2024-26143.

Comment 1 Marco Benatto 2024-02-27 18:18:27 UTC
Created rubygem-actionpack tracking bugs for this issue:

Affects: fedora-all [bug 2266389]


Created rubygem-rails-observers tracking bugs for this issue:

Affects: epel-7 [bug 2266390]