peter bassill · operator
$ cve CVE-2016-2098 JSON

CVE-2016-2098 EXPLOIT

7.3
HIGH · CVSS 3.0 · EPSS 81.4% (pctl 100)

Patch early

A public exploit exists.

Description

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

Scoring

CVSS7.3 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS81.45% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2016-04-07
Last modified2026-06-17

Affected (3)

VendorProduct
debiandebian linux
rubyonrailsrails
rubyonrailsruby on rails

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD