A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
| Software | From | Fixed in |
|---|---|---|
| rubyonrails / rails | 6.0.0 | 6.0.3.1 |
| rubyonrails / rails | - | 5.2.4.3 |
| debian / debian_linux | 8.0 | 8.0.x |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10.0 | 10.0.x |
| opensuse / leap | 15.1 | 15.1.x |
| opensuse / backports_sle | 15.0-sp1 | 15.0-sp1.x |
| opensuse / leap | 15.2 | 15.2.x |
actionpack
|
5.0.0 | 5.2.4.3 |
actionpack
|
6.0.0 | 6.0.3.1 |