Описание
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
Ссылки
EPSS
Процентиль: 44%
0.00214
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 1 года назад
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
CVSS3: 6.1
redhat
почти 3 года назад
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
CVSS3: 5.3
debian
около 1 года назад
There is a vulnerability in ActiveSupport if the new bytesplice method ...
CVSS3: 5.3
github
почти 3 года назад
Possible XSS Security Vulnerability in SafeBuffer#bytesplice
EPSS
Процентиль: 44%
0.00214
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-79