Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34185
HistoryFeb 14, 2022 - 5:34 a.m.

Information Disclosure

2022-02-1405:34:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.002 Low

EPSS

Percentile

59.7%

actionpack is vulnerable to information disclosure. The vulnerability exists in ActionDispatch::Executor which does not properly reset the thread for the next request because the library does not properly close the response body which will allow the attacker to gain access to sensitive data in subsequent requests.