Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0262

Опубликовано: 08 фев. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat CloudForms Tools 1rubygem-rackNot affected
Red Hat Enterprise MRG 2rubygem-rackNot affected
Red Hat Subscription Asset Managerrubygem-rackNot affected
RHEL 6 Version of OpenShift EnterprisejenkinsFixedRHSA-2013:063812.03.2013
RHEL 6 Version of OpenShift Enterpriseopenshift-origin-cartridge-jenkins-1.4FixedRHSA-2013:063812.03.2013
RHEL 6 Version of OpenShift Enterpriseruby193-rubygem-rackFixedRHSA-2013:063812.03.2013
RHEL 6 Version of OpenShift Enterpriserubygem-rackFixedRHSA-2013:063812.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=909072rubygem-rack: Path sanitization information disclosure

EPSS

Процентиль: 74%
0.00826
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

nvd
почти 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

debian
почти 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before ...

github
больше 8 лет назад

Rack Vulnerable to Path Traversal

EPSS

Процентиль: 74%
0.00826
Низкий

4.3 Medium

CVSS2