Description
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
Remediation
References
Related Vulnerabilities
WordPress Plugin Gmail SMTP Arbitrary File Disclosure (1.1.0)
Moodle Missing Authorization Vulnerability (CVE-2019-10187)
WordPress Plugin Collision Testimonials 'admin.php' SQL Injection (3.0)
Plone CMS Missing Authentication for Critical Function Vulnerability (CVE-2020-35190)
Rukovoditel Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-30224)