CVE-2024-28103: Rubyonrails Rails
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.
Affected products
- Rubyonrails Rails: from 6.1.0, before 6.1.7.8 (fixed in 6.1.7.8); from 7.0.0, before 7.0.8.4 (fixed in 7.0.8.4); from 7.1.0, before 7.1.3.4 (fixed in 7.1.3.4); version 7.2.0 only
Published 2024-06-04. Last modified 2026-06-17.