RubySec

Providing security resources for the Ruby community

CVE-2023-51763 (activeadmin): ActiveAdmin vulnerable to CSV injection

ActiveAdmin vulnerable to CSV injection

Published: December 24, 2023

SECURITY IDENTIFIERS

GEM

activeadmin

SEVERITY

CVSS v3.x: 8.4 (High)

PATCHED VERSIONS

>= 3.2.0

DESCRIPTION

csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.

RELATED