Rails is a web-application framework. Starting in version 7.1.0, there is a possible ReDoS vulnerability in the Accept header parsing routines of Action Dispatch. This vulnerability is patched in 7.1.3.1. Ruby 3.2 has mitigations for this problem, so Rails applications using Ruby 3.2 or newer are unaffected.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-02-27 16:15
Updated : 2024-05-03 13:15
NVD link : CVE-2024-26142
Mitre link : CVE-2024-26142
CVE.ORG link : CVE-2024-26142
JSON object : View
Products Affected
No product.
CWE
CWE-1333
Inefficient Regular Expression Complexity