[CVE-2024-47888] Possible ReDoS vulnerability in plain_text_for_blockquote_node in Action Text

Disclosed: 2024-11-28 22:15:01 By ooooooo_q To ibb
Low
Vulnerability Details
I made a report at https://hackerone.com/reports/2389431 https://discuss.rubyonrails.org/t/cve-2024-47888-possible-redos-vulnerability-in-plain-text-for-blockquote-node-in-action-text/87696 > There is a possible ReDoS vulnerability in the plain_text_for_blockquote_node helper in Action Text. This vulnerability has been assigned the CVE identifier CVE-2024-47888. ## Impact > Carefully crafted text can cause the plain_text_for_blockquote_node helper to take an unexpected amount of time, possibly resulting in a DoS vulnerability.
Actions
View on HackerOne
Report Stats
  • Report ID: 2792776
  • State: Closed
  • Substate: resolved
Share this report