漏洞描述 Ruby on Rails是Rails团队的一套基于Ruby语言的开源Web应用框架。 Ruby on Rails 5.2.5之前版本和6.0.4之前版本中存在代码问题漏洞。攻击者可利用该漏洞将不受信任的Ruby对象注入到Web应用程序,执行代码或造成其他危害。
相关漏洞推荐 POC CVE-2015-3224: Ruby on Rails Web Console - Remote Code Execution POC CVE-2018-3760: Ruby On Rails - Local File Inclusion POC CVE-2019-5418: Rails File Content Disclosure POC CVE-2020-8163: Ruby on Rails <5.0.1 - Remote Code Execution POC CVE-2021-33564: Ruby Dragonfly <1.4.0 - Remote Code Execution POC CVE-2018-3760: Ruby On Rails Path Traversal POC CVE-2019-5418: Rails File Content Disclosure POC privesc-ruby: Ruby - Privilege Escalation POC cmdi-ruby-open-rce: Ruby Kernel#open/URI.open RCE POC ruby-on-rails-framework-exceptions: Ruby on Rails Framework Exceptions POC rails-database-config: Ruby on Rails Database Configuration File - Detect POC environment-rb: Environment Ruby File Disclosure POC rails-secret-token-disclosure: Ruby on Rails Secret Token Disclosure