Slide 75
Slide 75 text
Name: actionpack
Version: 3.2.10
Advisory: OSVDB-103440
Name: actionpack
Version: 3.2.10
Advisory: OSVDB-89026
Criticality: High
URL: http://osvdb.org/show/osvdb/89026
Description:
Ruby on Rails contains a flaw in params_parser.rb of the Action Pack.
The issue is triggered when a type casting error occurs during
the parsing of parameters. This may allow a remote attacker to
potentially execute arbitrary code.
Solution: upgrade to ~> 2.3.15, ~> 3.0.19, ~> 3.1.10, >= 3.2.11
An example report from bunder-audit