Lack of data validation - Path Traversal In actionpack-page_caching
Description
Arbitrary file write in actionpack-page_caching gem There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 1.2.2-1 | ||
rubygems | 1.2.1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.