7.5

CVE-2016-2098

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DebianDebian Linux Version8.0
RubyonrailsRails Version4.0.0 Update-
RubyonrailsRails Version4.0.0 Updatebeta
RubyonrailsRails Version4.0.0 Updaterc1
RubyonrailsRails Version4.0.0 Updaterc2
RubyonrailsRails Version4.0.1 Update-
RubyonrailsRails Version4.0.1 Updaterc1
RubyonrailsRails Version4.0.1 Updaterc2
RubyonrailsRails Version4.0.1 Updaterc3
RubyonrailsRails Version4.0.1 Updaterc4
RubyonrailsRails Version4.0.2
RubyonrailsRails Version4.0.3
RubyonrailsRails Version4.0.4
RubyonrailsRails Version4.0.4 Updaterc1
RubyonrailsRails Version4.0.5
RubyonrailsRails Version4.0.6
RubyonrailsRails Version4.0.6 Updaterc1
RubyonrailsRails Version4.0.6 Updaterc2
RubyonrailsRails Version4.0.6 Updaterc3
RubyonrailsRails Version4.0.7
RubyonrailsRails Version4.0.8
RubyonrailsRails Version4.0.9
RubyonrailsRails Version4.0.10 Updaterc1
RubyonrailsRails Version4.1.0 Update-
RubyonrailsRails Version4.1.0 Updatebeta1
RubyonrailsRails Version4.1.0 Updatebeta2
RubyonrailsRails Version4.1.0 Updaterc1
RubyonrailsRails Version4.1.0 Updaterc2
RubyonrailsRails Version4.1.1
RubyonrailsRails Version4.1.2
RubyonrailsRails Version4.1.2 Updaterc1
RubyonrailsRails Version4.1.2 Updaterc2
RubyonrailsRails Version4.1.2 Updaterc3
RubyonrailsRails Version4.1.3
RubyonrailsRails Version4.1.4
RubyonrailsRails Version4.1.5
RubyonrailsRails Version4.1.6 Updaterc1
RubyonrailsRails Version4.1.6 Updaterc2
RubyonrailsRails Version4.1.7
RubyonrailsRails Version4.1.7.1
RubyonrailsRails Version4.1.8
RubyonrailsRails Version4.1.9 Updaterc1
RubyonrailsRails Version4.1.10 Updaterc1
RubyonrailsRails Version4.1.10 Updaterc2
RubyonrailsRails Version4.1.10 Updaterc3
RubyonrailsRails Version4.1.10 Updaterc4
RubyonrailsRails Version4.1.12 Updaterc1
RubyonrailsRails Version4.1.13 Updaterc1
RubyonrailsRails Version4.1.14 Updaterc1
RubyonrailsRails Version4.1.14 Updaterc2
RubyonrailsRails Version4.2.0 Updatebeta1
RubyonrailsRails Version4.2.0 Updatebeta2
RubyonrailsRails Version4.2.0 Updatebeta3
RubyonrailsRails Version4.2.0 Updatebeta4
RubyonrailsRails Version4.2.0 Updaterc1
RubyonrailsRails Version4.2.0 Updaterc2
RubyonrailsRails Version4.2.0 Updaterc3
RubyonrailsRails Version4.2.1
RubyonrailsRails Version4.2.1 Updaterc1
RubyonrailsRails Version4.2.1 Updaterc2
RubyonrailsRails Version4.2.1 Updaterc3
RubyonrailsRails Version4.2.1 Updaterc4
RubyonrailsRails Version4.2.2
RubyonrailsRails Version4.2.3
RubyonrailsRails Version4.2.3 Updaterc1
RubyonrailsRails Version4.2.4
RubyonrailsRails Version4.2.4 Updaterc1
RubyonrailsRails Version4.2.5
RubyonrailsRails Version4.2.5 Updaterc1
RubyonrailsRails Version4.2.5 Updaterc2
RubyonrailsRails Version4.2.5.1
RubyonrailsRuby On Rails Version <= 3.2.22.1
RubyonrailsRuby On Rails Version4.1.14.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 86.07% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.3 3.9 3.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.