RHSA-2016:0456-01 -- Redhat rh-ror41-rubygem-actionpack, rh-ror41-rubygem-actionviewID: oval:org.secpod.oval:def:504908 | Date: (C)2021-02-03 (M)2022-10-10 |
Class: PATCH | Family: unix |
The rh-ror41 collection provides Ruby on Rails version 4.1. Ruby on Rails is a model-view-controller framework for web application development. The following issues were corrected in rubygem-actionview: A directory traversal flaw was found in the way the Action View component searched for templates for rendering. If an application passed untrusted input to the "render" method, a remote, unauthenticated attacker could use this flaw to render unexpected files and, possibly, execute arbitrary code. A code injection flaw was found in the way the Action View component searched for templates for rendering. If an application passed untrusted input to the "render" method, a remote, unauthenticated attacker could use this flaw to execute arbitrary code. Red Hat would like to thank the Ruby on Rails project for reporting these issues. Upstream acknowledges Jyoti Singh and Tobias Kraze as original reporters of CVE-2016-2097, and Tobias Kraze and joernchen as original reporters of CVE-2016-2098. All rh-ror41 collection rubygem-actionview packages users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. All running applications using the rh-ror41 collection must be restarted for this update to take effect.
Platform: |
Red Hat Enterprise Linux 7 |
Red Hat Enterprise Linux 6 |
Product: |
rh-ror41-rubygem-actionpack |
rh-ror41-rubygem-actionview |