SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23633

In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request.

MEDIUM 5.9EPSS 2.23%

Does this matter?

Lower severity and a low EPSS score (2.23%). Track it; it rarely justifies an emergency change on its own.

Description

Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to reset thread local state for the next request. This can lead to data being leaked to subsequent requests.This has been fixed in Rails 7.0.2.1, 6.1.4.5, 6.0.4.5, and 5.2.6.1. Upgrading is highly recommended, but to work around this problem a middleware described in GHSA-wh98-p28r-vrc9 can be used.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
2.23% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-212
Affected
rubyonrails/rails · debian/debian linux
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.