Ruby on Rails params_parser.rb Action Pack Type Casting Parameter Parsing Remote Code Execution Vulnerability
14 Mar. 2013
Summary
Ruby on Rails params_parser.rb Action Pack Type Casting Parameter Parsing Remote suffers from code execution vulnerability.
Credit:
The information has been provided by Ben Murphy ,Magnus Holm, Felix Wilhelm ,Darcy Laycock ,Jonathan Rudenberg, Bryan Helmkamp ,Benoist Claassen, Charlie Somerville.
Vulnerable Systems:
* Ruby on Rails 3.2.10 and prior
Ruby on Rails contains a flaw in params_parser.rb of the Action Pack. The issue is triggered when a type casting error occurs during the parsing of parameters. This may allow a remote attacker to potentially execute arbitrary code.