CVE-2015-3224 | Ruby on Rails up to 3.x/4.x Web Console request.rb X-Forwarded-For Blacklist access control (EDB-41689 / Nessus ID 84255)
A vulnerability was found in Ruby on Rails up to 3.x/4.x. It has been classified as critical. Affected is an unknown function of the file request.rb of the component Web Console. The manipulation of the argument X-Forwarded-For leads to improper access controls (Blacklist).
This vulnerability is traded as CVE-2015-3224. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.