Rails -- XSS vulnerabilities

Affected packages
rubygem-actionpack52 <
rubygem-actionpack60 <
rubygem-actionpack61 <
rubygem-actionpack70 <
rubygem-actionview52 <
rubygem-actionview60 <
rubygem-actionview61 <
rubygem-actionview70 <


VuXML ID 9db93f3d-c725-11ec-9618-000d3ac47524
Discovery 2022-04-26
Entry 2022-04-30

Ruby on Rails blog:

This is an announcement to let you know that Rails,,, and have been released!

These are security releases so please update as soon as you can. Once again we've made these releases based on the last release tag, so hopefully upgrading will go smoothly.

The releases address two vulnerabilities, CVE-2022-22577, and CVS-2022-27777. They are both XSS vulnerabilities, so please take a look at the forum posts to see how (or if) they might possibly impact your application.


CVE Name CVE-2022-22577
CVE Name CVE-2022-27777