Description
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
Remediation
References
Related Vulnerabilities
Phusion Passenger Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-10345)
Apache Tomcat Exposure of Resource to Wrong Sphere Vulnerability (CVE-2017-5648)
Jetty Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2021-34429)
WordPress Plugin JobSearch WP Job Board Cross-Site Scripting (1.5.1)