actionpack

Page content
  • Author: kikadf
  • Vulnerable: 3.2.6-2arcturus1
  • Unaffected: 3.2.6-2arcturus2

The actionview/lib/action_view/helpers/number_helper.rb contains multiple cross-site scripting vulnerabilities. The actionpack/lib/action_view/template/text.rb performs symbol interning on MIME type strings, allowing remote denial-of-service attacks via increased memory consumption. A directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb allows remote attackers to read arbitrary files.

CVEs: