Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-0262

Опубликовано: 08 фев. 2013
Источник: redhat
CVSS2: 4.3

Описание

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise MRG 2rubygem-rackNot affected
Red Hat Subscription Asset Managerrubygem-rackNot affected
RHEL 6 Version of OpenShift EnterprisejenkinsFixedRHSA-2013:063812.03.2013
RHEL 6 Version of OpenShift Enterpriseopenshift-origin-cartridge-jenkins-1.4FixedRHSA-2013:063812.03.2013
RHEL 6 Version of OpenShift Enterpriseruby193-rubygem-rackFixedRHSA-2013:063812.03.2013
RHEL 6 Version of OpenShift Enterpriseruby193-rubygem-rackFixedRHSA-2013:063812.03.2013
RHEL 6 Version of OpenShift Enterpriserubygem-rackFixedRHSA-2013:063812.03.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=909072rubygem-rack: Path sanitization information disclosure

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

nvd
больше 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."

debian
больше 13 лет назад

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before ...

github
почти 9 лет назад

Rack Vulnerable to Path Traversal

4.3 Medium

CVSS2

Уязвимость CVE-2013-0262