VDB
Sign up
HIGH

GHSA-9wrq-xvmp-xjc8

Rails Denial of Service vulnerability

Quick fix

GHSA-9wrq-xvmp-xjc8 — rails: upgrade to the fixed version with the command below.

bundle update rails

Details

Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rails
Introduced in: 1.1.0Fixed in: 1.1.6
Fixbundle update rails

References