Back to Database
Status published
Unknown
CVE-2023-28120
There is a vulnerability in ActiveSupport if the new bytesplice...
Vulnerability Description
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-28120
Credits & Attribution
No credits recorded in the NVD database.
References
- https://discuss.rubyonrails.org/t/cve-2023-28120-possible-xss-security-vulnerability-in-safebuffer-bytesplice/82469
- https://github.com/rails/rails/commit/3cf23c3f891e2e81c977ea4ab83b62bc2a444b70
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UPV6PVCX4VDJHLFFT42EXBBSGAWZICOW/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZE5W4MH6IE4DV7GELDK6ISCSTFLHKSYO/
- https://security.netapp.com/advisory/ntap-20240202-0006/
- https://www.debian.org/security/2023/dsa-5389
More from Rails
View All →CVE-2025-24293
# Active Storage allowed transformation methods potentially unsafe
Active Storage attempts...
Critical
9.2
CVE-2023-38037
ActiveSupport::EncryptedFile writes contents that will be encrypted to a
temporary file....
Medium
5.5
CVE-2023-28362
The redirect_to method in Rails allows provided values to contain...
Unknown
0
CVE-2023-27539
There is a denial of service vulnerability in the header...
Unknown
0
CVE-2023-27531
There is a deserialization of untrusted data vulnerability in the...
Unknown
0
Affected Vendor
Rails
View all reports →Affected Software
ActiveSupport
Vulnerable Versions:
7.0.4.3, 6.1.7.3
Timeline
Official Publish:
January 9th, 2025
Last Modified:
January 9th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.