ZeroHour

CVE-2016-2098

CVSS 3.0
7.3 high
EPSS
81%p100
Published
()
Modified
Description

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

Vendors
debianrubyonrails
Products
debian linux, rails, ruby on rails
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.