actionpack Improper Input Validation vulnerability
Moderate severity
GitHub Reviewed
Published
Oct 24, 2017
to the GitHub Advisory Database
•
Updated Nov 12, 2023
Description
Published by the National Vulnerability Database
Feb 20, 2014
Published to the GitHub Advisory Database
Oct 24, 2017
Reviewed
Jun 16, 2020
Last updated
Nov 12, 2023
actionpack/lib/action_view/template/text.rb
in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the:text
option to therender
method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.References