There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| activesupport(RubyGems) | 7.0.0 | 7.0.4.3 | N/A |
| activesupport(RubyGems) | 0 | 6.1.7.3 | N/A |
CVSS Metrics