Описание
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
A directory traversal flaw was found in the way Ruby on Rails handled wildcard segments in routes with implicit rendering. A remote attacker could use this flaw to retrieve arbitrary local files accessible to a Ruby on Rails application using the aforementioned routes via a specially crafted request.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | ruby193-rubygem-actionpack | Will not fix | ||
| Red Hat OpenStack Platform 3 | ruby193-rubygem-actionpack | Will not fix | ||
| Red Hat OpenStack Platform 4 | ruby193-rubygem-actionpack | Will not fix | ||
| Red Hat Software Collections | ror40-rubygem-actionpack | Affected | ||
| Red Hat Subscription Asset Manager | rubygem-actionpack | Affected | ||
| CloudForms Management Engine 5.x | cfme | Fixed | RHSA-2014:0816 | 30.06.2014 |
| CloudForms Management Engine 5.x | ruby193-rubygem-actionpack | Fixed | RHSA-2014:0816 | 30.06.2014 |
| Red Hat Software Collections for RHEL-6 | ruby193-rubygem-actionpack | Fixed | RHSA-2014:0510 | 15.05.2014 |
| Red Hat Subscription Asset Manager 1.4 | katello | Fixed | RHSA-2014:1863 | 17.11.2014 |
| Red Hat Subscription Asset Manager 1.4 | ruby193-rubygem-actionmailer | Fixed | RHSA-2014:1863 | 17.11.2014 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS2
Связанные уязвимости
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
Directory traversal vulnerability in actionpack/lib/abstract_controlle ...
EPSS
7.5 High
CVSS2