Description
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
Remediation
References
Related Vulnerabilities
Liferay Portal Inefficient Regular Expression Complexity Vulnerability (CVE-2023-33950)
PHP Double Free Vulnerability (CVE-2016-5772)
MySQL CVE-2024-20975 Vulnerability (CVE-2024-20975)
WordPress Plugin Jigoshop Information Disclosure (1.17.9)
Oracle Application Server CVE-2006-0287 Vulnerability (CVE-2006-0287)