You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the locals argument of a render call to perform a RCE.
CVE-2020-8163 - High Severity Vulnerability
Simple, battle-tested conventions and helpers for building web pages.
Library home page: https://rubygems.org/gems/actionview-4.2.11.gem
Dependency Hierarchy:
Found in HEAD commit: 6942614fdaa22f54c101995c996e72ea6f6c9553
Found in base branch: master
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
locals
argument of arender
call to perform a RCE.Publish Date: 2020-07-02
URL: CVE-2020-8163
Base Score Metrics:
Type: Upgrade version
Origin: https://rubygems.org/gems/actionview/versions/5.0.1
Release Date: 2020-06-01
Fix Resolution: 5.0.1
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: