VDB

CVE-2023-23913

CVE-2023-23913 PUBLISHED CVSS 9.300000190734863 CRITICAL

Ruby on Rails ist ein in der Programmiersprache Ruby geschriebenes und quelloffenes Web Application Framework.

EPSS 0.21% · 43.7th percentile

Risk Scores

CVSS v4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.21%
43.7th percentile

Affected Products

VendorProductVersions
Open SourceOpen Source Ruby on Rails <7.0.4.3
DebianDebian Linux
Red HatRed Hat Enterprise Linux
Open SourceOpen Source Ruby on Rails <6.1.7.3
UbuntuUbuntu Linux
SUSESUSE Linux
AmazonAmazon Linux 2
SUSESUSE openSUSE
Red HatRed Hat OpenShift Logging Subsystem 5.7.2
FedoraFedora Linux

Timeline

  • CVE Published
  • Sep 7, 2023 PoC Published
  • Jan 9, 2025 EPSS Score
  • Jan 9, 2025 PoC Published
  • Jan 9, 2025 PoC Published
  • Jan 9, 2025 PoC Published
  • Jan 25, 2025 EPSS Score
  • Feb 9, 2025 EPSS Score
  • Feb 25, 2025 EPSS Score
  • Mar 13, 2025 EPSS Score
  • Mar 28, 2025 EPSS Score
  • Apr 13, 2025 EPSS Score

References

…and 14 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›