Code injection in Narou
Published: July 02, 2021
SECURITY IDENTIFIERS
- CVE: CVE-2021-35514 (NVD)
- GHSA: GHSA-gwrj-88fp-5m36
GEM
SEVERITY
CVSS v3.x: 8.5 (High)
PATCHED VERSIONS
>= 3.8.0
DESCRIPTION
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
