Description
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
Remediation
References
Related Vulnerabilities
WordPress Plugin Events Search For The Events Calendar Security Bypass (1.1.3)
PHP Other Vulnerability (CVE-2007-1452)
LimeSurvey Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2019-16184)
WordPress Plugin Contact Form Widget-Contact Query, Form Maker SQL Injection (1.0.9)
Atlassian Jira CVE-2021-26081 Vulnerability (CVE-2021-26081)