VDB
Sign up
HIGH

GHSA-rvpq-5xqx-pfpp

Ruby on Rails vulnerable to code injection

Quick fix

GHSA-rvpq-5xqx-pfpp — rails: upgrade to the fixed version with the command below.

bundle update rails

Details

Ruby on Rails before 1.1.5 allows remote attackers to execute Ruby code with "severe" or "serious" impact via a File Upload request with an HTTP header that modifies the LOAD_PATH variable, a different vulnerability than CVE-2006-4112.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rails
Introduced in: 1.1.0Fixed in: 1.1.6
Fixbundle update rails

References