Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13452
HistoryMar 14, 2019 - 2:16 a.m.

Remote Code Execution (RCE)

2019-03-1402:16:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.966 High

EPSS

Percentile

99.6%

railties is vulnerable to remote code execution. A remote attacker is able to guess the automatically generated secret token when Rails is in development mode. This token can subsequently be used in combination with other Rails internals to execute arbitrary code.