CVE-2016-2098: Debian Linux

High severity, CVSS 7.3. EPSS: 81.4% chance of exploitation in the next 30 days.

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Rubyonrails Rails: version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 4.0.4 only; version 4.0.5 only; …
  • Rubyonrails Ruby On Rails: up to and including 3.2.22.1; version 4.1.14.1 only

Published 2016-04-07. Last modified 2026-06-17.