Description
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
Remediation
References
Related Vulnerabilities
WordPress Plugin Catch Gallery Security Bypass (1.6.8)
WordPress Plugin YOP Poll Multiple Cross-Site Scripting Vulnerabilities (6.3.0)
Joomla! Core 3.x.x Cross-Site Scripting (3.7.0 - 3.10.6)
MongoDb Other Vulnerability (CVE-2020-7928)
WordPress Plugin News Element Elementor Blog Magazine Local File Inclusion (1.0.5)