DEBIAN-CVE-2024-28103
Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 04 Jun 2024, 20:15
Last modified:28 Apr 2026, 20:27
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.8 CRITICAL
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
04 Jun 2024, 20:15
Published
Vulnerability first disclosed
28 Apr 2026, 20:27
Last Modified
Vulnerability information updated
Description
Action Pack is a framework for handling and responding to web requests. Since 6.1.0, the application configurable Permissions-Policy is only served on responses with an HTML related Content-Type. This vulnerability is fixed in 6.1.7.8, 7.0.8.2, and 7.1.3.3.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Systems
- debian•rails
< 2:6.1.7.10+dfsg-1~deb12u1 | < 2:7.2.2.1+dfsg-1 | < 2:7.2.2.1+dfsg-1