CVE-2023-28120

Publication date

2025-01-09 00:33:47

Family

hackerone

State

PUBLISHED

Description

There is a vulnerability in ActiveSupport if the new bytesplice method is called on a SafeBuffer with untrusted user input.