Internet Bug Bounty: [CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text
Discription

There is a possible ReDoS vulnerability in the plain_text_for_blockquote_node helper in Action Text. This vulnerability has been assigned the CVE identifier CVE-2024-47888. Carefully crafted text was found to cause the plain_text_for_blockquote_node helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability. All users running an affected release were advised to either upgrade or apply the relevant patch immediately. Ruby 3.2 has been reported to have mitigations for this problem, so Rails applications using Ruby 3.2 or newer were unaffected. Rails 8.0.0.beta1, which depends on Ruby 3.2 or greater, was also…Read More
References
Back to Main