Description
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Cross-Site Request Forgery (3.7.0 - 3.9.18)
TYPO3 7PK - Security Features Vulnerability (CVE-2016-5091)
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-0792)
Oracle HTTP Server Improper Encoding or Escaping of Output Vulnerability (CVE-2022-25235)