Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an applicationβs unrestricted use of the render method.
lists.opensuse.org/opensuse-security-announce/2016-03/msg00057.html
lists.opensuse.org/opensuse-security-announce/2016-03/msg00080.html
lists.opensuse.org/opensuse-security-announce/2016-03/msg00083.html
lists.opensuse.org/opensuse-security-announce/2016-03/msg00086.html
lists.opensuse.org/opensuse-security-announce/2016-04/msg00006.html
lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.html
weblog.rubyonrails.org/2016/2/29/Rails-4-2-5-2-4-1-14-2-3-2-22-2-have-been-released
www.debian.org/security/2016/dsa-3509
github.com/rails/rails
github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2016-2098.yml
groups.google.com/forum/#!topic/rubyonrails-security/ly-IH-fxr_Q
nvd.nist.gov/vuln/detail/CVE-2016-2098
web.archive.org/web/20200228015318/www.securityfocus.com/bid/83725
web.archive.org/web/20210612214217/https://groups.google.com/forum/message/raw?msg=rubyonrails-security/ly-IH-fxr_Q/WLoOhcMZIAAJ
web.archive.org/web/20211205173437/https://securitytracker.com/id/1035122
www.exploit-db.com/exploits/40086