VDB
KO
HIGH

GHSA-rvpq-5xqx-pfpp

Ruby on Rails vulnerable to code injection

Details

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / rails
Introduced in: 1.1.0 Fixed in: 1.1.6
Fix bundle update rails

References