The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| actionview(RubyGems) | 0 | 4.2.11.3 | N/A |
CVSS Metrics