GHSA-9wrq-xvmp-xjc8

Suggest an improvement
Source
https://github.com/advisories/GHSA-9wrq-xvmp-xjc8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-9wrq-xvmp-xjc8/GHSA-9wrq-xvmp-xjc8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9wrq-xvmp-xjc8
Aliases
Published
2017-10-24T18:33:38Z
Modified
2024-11-28T05:34:08.735730Z
Summary
High severity vulnerability that affects rails.
Details

Unspecified vulnerability in the "dependency resolution mechanism" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or "data loss," a different vulnerability than CVE-2006-4111.

Database specific
{
    "nvd_published_at": "2006-08-14T21:04:00Z",
    "cwe_ids": [],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:29:44Z"
}
References

Affected packages

RubyGems / rails

Package

Name
rails
Purl
pkg:gem/rails

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.1.0
Fixed
1.1.6

Affected versions

1.*

1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5