Description
The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.
Remediation
References
Related Vulnerabilities
Oracle JRE CVE-2013-2433 Vulnerability (CVE-2013-2433)
Roundcube Resource Management Errors Vulnerability (CVE-2008-5620)
WordPress Plugin AP Companion includes Backdoor [Only if downloaded via the vendor website] (1.0.6)
OpenVPN AS Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2020-36382)
Atlassian Jira CVE-2019-20418 Vulnerability (CVE-2019-20418)