VYPR

Actionpack Page Caching

by Rubyonrails

CVEs (2)

  • CVE-2020-8159CriMay 12, 2020
    risk 0.57cvss 9.8epss 0.05

    There is a vulnerability in actionpack_page-caching gem < v1.2.1 that allows an attacker to write arbitrary files to a web server, potentially resulting in remote code execution if the attacker can write unescaped ERB to a view.

  • CVE-2021-22885HigMay 27, 2021
    risk 0.49cvss 7.5epss 0.04

    A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `redirect_to` or `polymorphic_url`helper with untrusted user input.