Action Pack is a framework for handling and responding to web requests. There is a possible Cross Site Scripting (XSS) vulnerability in the content_security_policy helper starting in version 5.2.0 of Action Pack and prior to versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and 8.0.0.1. Applications which set Content-Security-Policy (CSP) headers dynamically from untrusted user input may be vulnerable to carefully crafted inputs being able to inject new directives into the CSP. This could lead to a bypass of the CSP and its protection against XSS and other attacks. Versions 7.0.8.7, 7.1.5.1, 7.2.2.1, and 8.0.0.1 contain a fix. As a workaround, applications can avoid setting CSP headers dynamically from untrusted input, or can validate/sanitize that input.
{
"binaries": [
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "rails"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-actioncable"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-actionmailbox"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-actionmailer"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-actionpack"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-actiontext"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-actionview"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-activejob"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-activemodel"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-activerecord"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-activestorage"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-activesupport"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-rails"
},
{
"binary_version": "2:6.1.7.3+dfsg-3",
"binary_name": "ruby-railties"
}
]
}{
"binaries": [
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "rails"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-actioncable"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-actionmailbox"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-actionmailer"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-actionpack"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-actiontext"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-actionview"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-activejob"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-activemodel"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-activerecord"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-activestorage"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-activesupport"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-rails"
},
{
"binary_version": "2:6.1.7.3+dfsg-7",
"binary_name": "ruby-railties"
}
]
}{
"binaries": [
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "rails"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-actioncable"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-actionmailbox"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-actionmailer"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-actionpack"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-actiontext"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-actionview"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-activejob"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-activemodel"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-activerecord"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-activestorage"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-activesupport"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-rails"
},
{
"binary_version": "2:7.2.2.1+dfsg-7",
"binary_name": "ruby-railties"
}
]
}{
"binaries": [
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "rails"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-actionmailer"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-actionpack"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-actionview"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-activejob"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-activemodel"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-activerecord"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-activesupport"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-rails"
},
{
"binary_version": "2:4.2.6-1ubuntu0.1~esm2",
"binary_name": "ruby-railties"
}
]
}{
"binaries": [
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "rails"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-actionmailer"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-actionpack"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-actionview"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-activejob"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-activemodel"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-activerecord"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-activesupport"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-rails"
},
{
"binary_version": "2:4.2.10-0ubuntu4+esm2",
"binary_name": "ruby-railties"
}
]
}{
"binaries": [
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "rails"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-actioncable"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-actionmailer"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-actionpack"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-actionview"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-activejob"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-activemodel"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-activerecord"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-activestorage"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-activesupport"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-rails"
},
{
"binary_version": "2:5.2.3+dfsg-3ubuntu0.1~esm1",
"binary_name": "ruby-railties"
}
]
}{
"binaries": [
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "rails"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-actioncable"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-actionmailbox"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-actionmailer"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-actionpack"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-actiontext"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-actionview"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-activejob"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-activemodel"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-activerecord"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-activestorage"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-activesupport"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-rails"
},
{
"binary_version": "2:6.1.4.1+dfsg-8ubuntu2+esm1",
"binary_name": "ruby-railties"
}
]
}