CVE-2016-2098

Description

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an applications unrestricted use of the render method.

Risk Information

Base Score
7.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
87.43

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-2097,CVE-2016-2098 are fixed in Ruby-actionpack 3.2.22.2Windows
Vulnerabilities CVE-2016-2097,CVE-2016-2098 are fixed in Ruby-actionpack 4.1.14.2Windows
Vulnerabilities CVE-2016-2098 are fixed in Ruby-actionpack 4.2.5.2Windows
Vulnerabilities CVE-2016-2097,CVE-2016-2098 are fixed in Ruby-actionpack for Linux 3.2.22.2Linux
Vulnerabilities CVE-2016-2097,CVE-2016-2098 are fixed in Ruby-actionpack for Linux 4.1.14.2Linux
Vulnerabilities CVE-2016-2098 are fixed in Ruby-actionpack for Linux 4.2.5.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234