Описание
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
A code injection flaw was found in the way Action View component searched for templates for rendering. If an application passed untrusted input to the 'render' method, a remote, unauthenticated attacker could use this flaw to execute arbitrary code.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| CloudForms Management Engine 5.2 | ruby193-rubygem-actionpack | Affected | ||
| CloudForms Management Engine 5.3 | ruby193-rubygem-actionpack | Affected | ||
| Red Hat Software Collections | rh-ror42-rubygem-actionview | Not affected | ||
| Red Hat Subscription Asset Manager | ruby193-rubygem-actionpack | Will not fix | ||
| Red Hat Subscription Asset Manager | rubygem-actionpack | Will not fix | ||
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | ror40-rubygem-actionpack | Fixed | RHSA-2016:0454 | 15.03.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | ror40-rubygem-activerecord | Fixed | RHSA-2016:0454 | 15.03.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | ror40-rubygem-activesupport | Fixed | RHSA-2016:0454 | 15.03.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | ruby193-rubygem-actionpack | Fixed | RHSA-2016:0455 | 15.03.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | ruby193-rubygem-activerecord | Fixed | RHSA-2016:0455 | 15.03.2016 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.8 Medium
CVSS2
Связанные уязвимости
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and ...
actionpack allows remote code execution via application's unrestricted use of render method
EPSS
6.8 Medium
CVSS2