{"id":"CVE-2024-26144","aliases":["BIT-rails-2024-26144","GHSA-8h22-8cf7-hq6g"],"url":"https://o3.security/vulnerability/CVE-2024-26144","summary":"Possible Sensitive Session Information Leak in Active Storage","details":"# Possible Sensitive Session Information Leak in Active Storage\n\nThere is a possible sensitive session information leak in Active Storage.  By\ndefault, Active Storage sends a `Set-Cookie` header along with the user's\nsession cookie when serving blobs.  It also sets `Cache-Control` to public.\nCertain proxies may cache the Set-Cookie, leading to an information leak.\n\nThis vulnerability has been assigned the CVE identifier CVE-2024-26144.\n\nVersions Affected:  >= 5.2.0, < 7.1.0\nNot affected:       < 5.2.0, > 7.1.0\nFixed Versions:     7.0.8.1, 6.1.7.7\n\nImpact\n------\nA proxy which chooses to caches this request can cause users to share\nsessions. This may include a user receiving an attacker's session or vice\nversa.\n\nThis was patched in 7.1.0 but not previously identified as a security\nvulnerability.\n\nAll users running an affected release should either upgrade or use one of the\nworkarounds immediately.\n\nReleases\n--------\nThe fixed releases are available at the normal locations.\n\nWorkarounds\n-----------\nUpgrade to Rails 7.1.X, or configure caching proxies not to cache the\nSet-Cookie headers.\n\nCredits\n-------\n\nThanks to [tyage](https://hackerone.com/tyage) for reporting this!","published":"2024-02-27T15:44:04.166Z","modified":"2026-09-09T03:45:35.340996443Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":{"score":0.01129,"percentile":0.64788,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"activestorage","fixedVersion":"6.1.7.7"},{"ecosystem":"RubyGems","name":"activestorage","fixedVersion":"7.0.8.1"}],"fix":{"url":"https://github.com/rails/rails/commit/723f54566023e91060a67b03353e7c03e7436433","label":"rails/rails@723f545"},"references":[{"type":"WEB","url":"https://discuss.rubyonrails.org/t/possible-sensitive-session-information-leak-in-active-storage/84945"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/26xxx/CVE-2024-26144.json"},{"type":"ADVISORY","url":"https://github.com/rails/rails/security/advisories/GHSA-8h22-8cf7-hq6g"},{"type":"ADVISORY","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activestorage/CVE-2024-26144.yml"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26144"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240510-0013/"},{"type":"FIX","url":"https://github.com/rails/rails/commit/723f54566023e91060a67b03353e7c03e7436433"},{"type":"FIX","url":"https://github.com/rails/rails/commit/78fe149509fac5b05e54187aaaef216fbb5fd0d3"},{"type":"PACKAGE","url":"https://github.com/rails/rails"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2024-26144.yml"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20240510-0013"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T03:45:35.340996443Z"}}