{"id":"GHSA-8h22-8cf7-hq6g","summary":"Rails has possible Sensitive Session Information Leak in Active Storage","details":"# Possible Sensitive Session Information Leak in Active Storage\n\nThere is a possible sensitive session information leak in Active Storage.  By\ndefault, Active Storage sends a `Set-Cookie` header along with the user's\nsession cookie when serving blobs.  It also sets `Cache-Control` to public.\nCertain proxies may cache the Set-Cookie, leading to an information leak.\n\nThis vulnerability has been assigned the CVE identifier CVE-2024-26144.\n\nVersions Affected:  \u003e= 5.2.0, \u003c 7.1.0\nNot affected:       \u003c 5.2.0, \u003e 7.1.0\nFixed Versions:     7.0.8.1, 6.1.7.7\n\nImpact\n------\nA proxy which chooses to caches this request can cause users to share\nsessions. This may include a user receiving an attacker's session or vice\nversa.\n\nThis was patched in 7.1.0 but not previously identified as a security\nvulnerability.\n\nAll users running an affected release should either upgrade or use one of the\nworkarounds immediately.\n\nReleases\n--------\nThe fixed releases are available at the normal locations.\n\nWorkarounds\n-----------\nUpgrade to Rails 7.1.X, or configure caching proxies not to cache the\nSet-Cookie headers.\n\nCredits\n-------\n\nThanks to [tyage](https://hackerone.com/tyage) for reporting this!","aliases":["BIT-rails-2024-26144","CVE-2024-26144"],"modified":"2026-09-10T03:50:05.469654069Z","published":"2024-02-27T21:41:16Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-02-27T21:41:16Z","nvd_published_at":"2024-02-27T16:15:46Z","cwe_ids":["CWE-200"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/rails/rails/security/advisories/GHSA-8h22-8cf7-hq6g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26144"},{"type":"WEB","url":"https://github.com/rails/rails/commit/723f54566023e91060a67b03353e7c03e7436433"},{"type":"WEB","url":"https://github.com/rails/rails/commit/78fe149509fac5b05e54187aaaef216fbb5fd0d3"},{"type":"WEB","url":"https://discuss.rubyonrails.org/t/possible-sensitive-session-information-leak-in-active-storage/84945"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2024-26144.yml"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2024-26144.yml"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240510-0013"}],"affected":[{"package":{"name":"activestorage","ecosystem":"RubyGems","purl":"pkg:gem/activestorage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.2.0"},{"fixed":"6.1.7.7"}]}],"versions":["5.2.0","5.2.1","5.2.1.1","5.2.1.rc1","5.2.2","5.2.2.1","5.2.2.rc1","5.2.3","5.2.3.rc1","5.2.4","5.2.4.1","5.2.4.2","5.2.4.3","5.2.4.4","5.2.4.5","5.2.4.6","5.2.4.rc1","5.2.5","5.2.6","5.2.6.1","5.2.6.2","5.2.6.3","5.2.7","5.2.7.1","5.2.8","5.2.8.1","6.0.0","6.0.0.beta1","6.0.0.beta2","6.0.0.beta3","6.0.0.rc1","6.0.0.rc2","6.0.1","6.0.1.rc1","6.0.2","6.0.2.1","6.0.2.2","6.0.2.rc1","6.0.2.rc2","6.0.3","6.0.3.1","6.0.3.2","6.0.3.3","6.0.3.4","6.0.3.5","6.0.3.6","6.0.3.7","6.0.3.rc1","6.0.4","6.0.4.1","6.0.4.2","6.0.4.3","6.0.4.4","6.0.4.5","6.0.4.6","6.0.4.7","6.0.4.8","6.0.5","6.0.5.1","6.0.6","6.0.6.1","6.1.0","6.1.0.rc1","6.1.0.rc2","6.1.1","6.1.2","6.1.2.1","6.1.3","6.1.3.1","6.1.3.2","6.1.4","6.1.4.1","6.1.4.2","6.1.4.3","6.1.4.4","6.1.4.5","6.1.4.6","6.1.4.7","6.1.5","6.1.5.1","6.1.6","6.1.6.1","6.1.7","6.1.7.1","6.1.7.2","6.1.7.3","6.1.7.4","6.1.7.5","6.1.7.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-8h22-8cf7-hq6g/GHSA-8h22-8cf7-hq6g.json"}},{"package":{"name":"activestorage","ecosystem":"RubyGems","purl":"pkg:gem/activestorage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.0.8.1"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.0.2.1","7.0.2.2","7.0.2.3","7.0.2.4","7.0.3","7.0.3.1","7.0.4","7.0.4.1","7.0.4.2","7.0.4.3","7.0.5","7.0.5.1","7.0.6","7.0.7","7.0.7.1","7.0.7.2","7.0.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-8h22-8cf7-hq6g/GHSA-8h22-8cf7-hq6g.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}