Remote code execution via user-provided local names in ActionView
High severity
GitHub Reviewed
Published
Jul 7, 2020
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Description
Published by the National Vulnerability Database
Jul 2, 2020
Reviewed
Jul 7, 2020
Published to the GitHub Advisory Database
Jul 7, 2020
Last updated
Jul 5, 2023
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that would allow an attacker who controlled the
locals
argument of arender
call to perform a RCE.References