Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian 9: DLA-2655-1 Moderate: Rails Info Disclosure and DoS Threats

debian lts
Calendar Grey May 11, 2021
Dist Debian Esm H88
This notification highlights security risks in Django for Ubuntu LTS, recommending updates to mitigate exposure and denial-of-service risks.
CVE-2021-22885 There is a possible information disclosure/unintended method execution vulnerability in Action Pack when using the

Summary

There is a possible information disclosure/unintended method
execution vulnerability in Action Pack when using the
`redirect_to` or `polymorphic_url` helper with untrusted user
input.

CVE-2021-22904

There is a possible DoS vulnerability in the Token Authentication
logic in Action Controller. Impacted code uses
`authenticate_or_request_with_http_token` or
`authenticate_with_http_token` for request authentication.

For Debian 9 stretch, these problems have been fixed in version
2:4.2.7.1-1+deb9u5.

We recommend that you upgrade your rails packages.

For the detailed security status of rails please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/rails

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: rails
Version: 2:4.2.7.1-1+deb9u5
CVE ID: CVE-2021-22885 CVE-2021-22904
Debian Bug: 988214

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here