CVE-2023-28120: Rails Activesupport
Medium severity, CVSS 5.3. EPSS: 0.9% chance of exploitation in the next 30 days.
There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.
Affected products
- Rails Activesupport: from 7, before 7.0.4.3 (fixed in 7.0.4.3); from 6, before 6.1.7.3 (fixed in 6.1.7.3)
Published 2025-01-09. Last modified 2026-06-17.