Lack of data validation In actionpack
Description
actionpack allows remote code execution via application's unrestricted use of render method Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rubygems | 3.2.22.2, 4.1.14.2, 4.2.5.2 | ||
rubygems | 4.2.5.2 | ||
debian 12 | 2:4.2.5.2-1 | ||
debian 13 | 2:4.2.5.2-1 | ||
debian 14 | 2:4.2.5.2-1 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16.