[WID-SEC-2026-2574] Ruby on Rails: Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 10.0 (kritisch) CVSS Temporal Score 8.7 (hoch) Remoteangriff ja Datum 29.07.2026 Stand 30.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Produktbeschreibung Ruby on Rails ist ein in der Programmiersprache Ruby geschriebenes und quelloffenes Web Application Framework. Produkte 29.07.2026 Open Source Ruby on Rails <7.2.3.2 Open Source Ruby on Rails <8.0.5.1 Open Source Ruby on Rails <8.1.3.1 Open Source Ruby on Rails libvips <8.13 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Ruby on Rails ausnutzen, um Informationen offenzulegen, was möglicherweise zur Remote-Codeausführung oder zu lateraler Bewegung führen kann. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical information disclosure vulnerability in Ruby on Rails (CVSS Base Score 10.0) can be exploited by a remote, anonymous attacker, potentially leading to remote code execution or lateral movement. Affected versions include Ruby on Rails versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1, as well as libvips prior to version 8.13. A mitigation is available, requiring an upgrade to the specified patched versions.