Arbitrary file write in actionpack-page_caching gem
Critical severity
GitHub Reviewed
Published
May 13, 2020
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 12, 2020
Reviewed
May 13, 2020
Published to the GitHub Advisory Database
May 13, 2020
Last updated
Feb 1, 2023
There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.
References