Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rageltman

#36204of 53,630
7.5Total CVSS
Vulnerabilities · 1
PT-2016-5015
7.5
2016-03-09
Ruby · Ruby On Rails · CVE-2016-2098
**Name of the Vulnerable Software and Affected Versions** Ruby on Rails versions 3.2.x through 3.2.22.1 Ruby on Rails versions 4.0.x through 4.1.14.1 Ruby on Rails versions 4.2.x through 4.2.5.1 **Description** The issue allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method. **Recommendations** For versions 3.2.x through 3.2.22.1, update to version 3.2.22.2 or later. For versions 4.0.x through 4.1.14.1, update to version 4.1.14.2 or later. For versions 4.2.x through 4.2.5.1, update to version 4.2.5.2 or later.