CVE-2023-51763

csv_builder.rb in ActiveAdmin (aka Active Admin) before 3.2.0 allows CSV injection.
Configurations

Configuration 1 (hide)

cpe:2.3:a:activeadmin:active_admin:*:*:*:*:*:ruby_on_rails:*:*

History

03 Jan 2024, 20:54

Type Values Removed Values Added
CPE cpe:2.3:a:activeadmin:active_admin:*:*:*:*:*:ruby_on_rails:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Activeadmin active Admin
Activeadmin
CWE CWE-1236
References () https://github.com/activeadmin/activeadmin/commit/697be2b183491beadc8f0b7d8b5bfb44f2387909 - () https://github.com/activeadmin/activeadmin/commit/697be2b183491beadc8f0b7d8b5bfb44f2387909 - Patch
References () https://github.com/activeadmin/activeadmin/pull/8161 - () https://github.com/activeadmin/activeadmin/pull/8161 - Patch
References () https://github.com/activeadmin/activeadmin/releases/tag/v3.2.0 - () https://github.com/activeadmin/activeadmin/releases/tag/v3.2.0 - Release Notes

24 Dec 2023, 04:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-24 04:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-51763

Mitre link : CVE-2023-51763

CVE.ORG link : CVE-2023-51763


JSON object : View

Products Affected

activeadmin

  • active_admin
CWE
CWE-1236

Improper Neutralization of Formula Elements in a CSV File