← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE EPSS 0.28

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our…

Číst originál na Rapid7 →

3 zprávy z 2 zdrojů · první 30. 7. 18:11 · poslední 3. 8. 19:11 CZ · EN/orig

Ruby on Rails US IT

tg: zranitelnost tg: novinka v produktu

CVE v události 1

CVEhodnoceníKEVEPSS
CVE-2026-66066 9.5 4.0 · GitHub_M 0.28

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.5.

Jak se o tom psalo 3

  1. · Rapid7 US nadpis události

    Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

    OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our…

  2. · CSIRT Itálie (ACN) IT

    Rilevata vulnerabilità in Ruby on Rails

    Rilasciato aggiornamento per risolvere una vulnerabilità di sicurezza con gravità “critica” in Ruby on Rails, noto framework open source per lo sviluppo di applicazioni web, scritto nel linguaggio di programmazione Ruby. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato la lettura di file arbitrari sul filesystem dei sistemi interessati e, in particolari condizioni, l'esecuzione di codice arbitrario.

  3. · Rapid7 US

    KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails

    OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of a Resource with an Insecure Default (CWE-1188). An unauthenticated attacker may be able to leverage CVE-2026-66066 and read files accessible to the Rails application process,…