漏洞信息详情
Rails Action Pack 信息泄露漏洞
漏洞简介
Rails Action Pack是美国Rails社区的一个web框架。提供了路由机制(将请求URL映射到动作),定义实现动作的控制器以及通过渲染视图(各种格式的模板)生成响应的机制。
Action Pack存在信息泄露漏洞,该漏洞源于网络系统或产品在运行过程中存在配置等错误。未授权的攻击者可利用漏洞获取受影响组件敏感信息。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://weblog.rubyonrails.org/2021/5/5/Rails-versions-6-1-3-2-6-0-3-7-5-2-4-6-and-5-2-6-have-been-released/
参考网址
来源:MISC
链接:https://hackerone.com/reports/1106652
来源:DEBIAN
链接:https://www.debian.org/security/2021/dsa-4929
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-security-vulnerability-in-ruby-on-rails-affects-ibm-cloud-pak-for-multicloud-management-infrastructure-management/
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021051012
来源:vigilance.fr
链接:https://vigilance.fr/vulnerability/rails-two-vulnerabilities-35391
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1751
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1596
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.3919
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.1830
来源:www.ibm.com
链接:https://www.ibm.com/blogs/psirt/security-bulletin-a-vulnerability-in-ruby-on-rails-affects-ibm-license-metric-tool-v9-cve-2021-22885/
来源:access.redhat.com
链接:https://access.redhat.com/security/cve/cve-2021-22885
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2021.2084
来源:packetstormsecurity.com
链接:https://packetstormsecurity.com/files/164991/Red-Hat-Security-Advisory-2021-4702-01.html
来源:www.cybersecurity-help.cz
链接:https://www.cybersecurity-help.cz/vdb/SB2021061020
受影响实体
暂无
补丁
- Rails Action Pack 信息泄露漏洞的修复措施<!--2021-5-5-->
还没有评论,来说两句吧...