é«åº¦è¨ºæé¨ã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£èª²ã®å±±å´ã§ãã å¼ç¤¾ã¨ã³ã¸ãã¢ã®åå¤å±ã¨å±±å´ãRuby on Railsã®Active Storageã®èå¼±æ§CVE-2024-26144ãå ±åãã¾ããã æ¬èå¼±æ§ã¯Railsã®5.2.0ãã7.1.0ã®ãã¼ã¸ã§ã³ã«å½±é¿ãããã®ã§ãã使ãã®Railsã®ãã¼ã¸ã§ã³ãææ°ã§ãªãå ´åã«ã¯ã¢ãããã¼ããæ¨å¥¨ãã¾ãã æ¬è¨äºã§ã¯æ¬èå¼±æ§ã®æ³¨æç¹ã¨ãé¢é£ãã¦Cookieã®ãã£ãã·ã¥ã«é¢ãã調æ»å 容ãç´¹ä»ãã¾ãã TL;DR ã» Set-Cookieãããããã£ãã·ã¥ãããã¨å¥äººãã°ã¤ã³åé¡ãçºçãã ã» Railsã®Active Storageã§Set-Cookieãããããã£ãã·ã¥å¯è½ãªè¨å®ã§ãã£ã(CVE-2024-26144) ã» Nginx(+ Passenger), Apache(+ mod_cache)çã®ãã£ãã·ã¥æ©æ§ã¨åããã¦å©ç¨ããã¨å®éã«äºæ ã
{{#tags}}- {{label}}
{{/tags}}