CVE-2016-0752
גבוהה 7.5 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Ruby on Rails Directory Traversal Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 96% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-22
מוצרים מושפעים
rubyonrails: rails; opensuse: leap; opensuse: opensuse; suse: linux enterprise module for containers; debian: debian linux; redhat: software collections
קישורים
- http://www.openwall.com/lists/oss-security/2016/01/25/13 ExploitMailing List
- https://www.exploit-db.com/exploits/40561/ ExploitThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2016/01/25/13 ExploitMailing List
- https://www.exploit-db.com/exploits/40561/ ExploitThird Party AdvisoryVDB Entry
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178044… Permissions Required
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178069… Permissions Required
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.html Mailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.html Mailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0296.html Third Party Advisory