diff --git a/advisories/github-reviewed/2024/12/GHSA-vfm5-rmrh-j26v/GHSA-vfm5-rmrh-j26v.json b/advisories/github-reviewed/2024/12/GHSA-vfm5-rmrh-j26v/GHSA-vfm5-rmrh-j26v.json index e2ea158e646..684a8b4c745 100644 --- a/advisories/github-reviewed/2024/12/GHSA-vfm5-rmrh-j26v/GHSA-vfm5-rmrh-j26v.json +++ b/advisories/github-reviewed/2024/12/GHSA-vfm5-rmrh-j26v/GHSA-vfm5-rmrh-j26v.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-vfm5-rmrh-j26v", - "modified": "2024-12-10T22:42:27Z", + "modified": "2024-12-11T16:15:12Z", "published": "2024-12-10T22:42:27Z", "aliases": [ "CVE-2024-54133" ], "summary": "Possible Content Security Policy bypass in Action Dispatch", "details": "There is a possible Cross Site Scripting (XSS) vulnerability in the `content_security_policy` helper in Action Pack.\n\nImpact\n------\nApplications which set Content-Security-Policy (CSP) headers dynamically from untrusted user input may be vulnerable to carefully crafted inputs being able to inject new directives into the CSP. This could lead to a bypass of the CSP and its protection against XSS and other attacks.\n\nReleases\n--------\nThe fixed releases are available at the normal locations.\n\nWorkarounds\n-----------\nApplications can avoid setting CSP headers dynamically from untrusted input, or can validate/sanitize that input.\n\nCredits\n-------\nThanks to [ryotak](https://hackerone.com/ryotak) for the report!\n", - "severity": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], "affected": [ { "package": { @@ -92,6 +97,26 @@ "type": "WEB", "url": "https://github.com/rails/rails/security/advisories/GHSA-vfm5-rmrh-j26v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54133" + }, + { + "type": "WEB", + "url": "https://github.com/rails/rails/commit/2e3f41e4538b9ca1044357f6644f037bbb7c6c49" + }, + { + "type": "WEB", + "url": "https://github.com/rails/rails/commit/3da2479cfe1e00177114b17e496213c40d286b3a" + }, + { + "type": "WEB", + "url": "https://github.com/rails/rails/commit/5558e72f22fc69c1c407b31ac5fb3b4ce087b542" + }, + { + "type": "WEB", + "url": "https://github.com/rails/rails/commit/cb16a3bb515b5d769f73926d9757270ace691f1d" + }, { "type": "PACKAGE", "url": "https://github.com/rails/rails" @@ -104,6 +129,6 @@ "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-12-10T22:42:27Z", - "nvd_published_at": null + "nvd_published_at": "2024-12-10T23:15:06Z" } } \ No newline at end of file