FreeBSD : rubygem-rails -- multiple vulnerabilities (eb8a8978-8dd5-49ce-87f4-49667b2166dd)

medium Nessus Plugin ID 84255

Synopsis

The remote FreeBSD host is missing one or more security-related updates.

Description

Ruby on Rails blog :

Rails 3.2.22, 4.1.11 and 4.2.2 have been released, along with web console and jquery-rails plugins and Rack 1.5.4 and 1.6.2.

Solution

Update the affected packages.

See Also

http://www.nessus.org/u?e7e44bdf

http://www.nessus.org/u?1d94a7dc

Plugin Details

Severity: Medium

ID: 84255

File Name: freebsd_pkg_eb8a89788dd549ce87f449667b2166dd.nasl

Version: 2.7

Type: local

Published: 6/18/2015

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:rubygem-activesupport, p-cpe:/a:freebsd:freebsd:rubygem-activesupport4, p-cpe:/a:freebsd:freebsd:rubygem-jquery-rails, p-cpe:/a:freebsd:freebsd:rubygem-jquery-rails4, p-cpe:/a:freebsd:freebsd:rubygem-rack, p-cpe:/a:freebsd:freebsd:rubygem-rack15, p-cpe:/a:freebsd:freebsd:rubygem-rack16, p-cpe:/a:freebsd:freebsd:rubygem-rails, p-cpe:/a:freebsd:freebsd:rubygem-rails4, p-cpe:/a:freebsd:freebsd:rubygem-web-console, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/17/2015

Vulnerability Publication Date: 6/16/2015

Exploitable With

Metasploit (Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution)

Reference Information

CVE: CVE-2015-1840, CVE-2015-3224, CVE-2015-3225, CVE-2015-3226, CVE-2015-3227