Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2098

Опубликовано: 07 апр. 2016
Источник: debian

Описание

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
railsfixed2:4.2.5.2-1package
railsnot-affectedwheezypackage
railsend-of-lifesqueezepackage
ruby-actionpack-3.2removedpackage
ruby-actionpack-2.3removedpackage
ruby-actionpack-2.3end-of-lifewheezypackage

Примечания

  • Versions Affected: 3.2.x, 4.0.x, 4.1.x, 4.2.x

  • Fixed Versions: 3.2.22.2, 4.1.14.2, 4.2.5.2

Связанные уязвимости

CVSS3: 7.3
ubuntu
почти 10 лет назад

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

redhat
почти 10 лет назад

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

CVSS3: 7.3
nvd
почти 10 лет назад

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

suse-cvrf
почти 10 лет назад

Security update for rubygem-actionview-4_2

CVSS3: 7.3
github
больше 8 лет назад

actionpack allows remote code execution via application's unrestricted use of render method