Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-17042

Опубликовано: 24 нояб. 2017
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.

Отчет

This issue affects the versions of rubygem-yard as shipped with Red Hat Subscription Asset Manager 1.x and Message Routing and Grid 2.x. Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise MRG 2rubygem-yardWill not fix
Red Hat Subscription Asset Managerrubygem-yardWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1519065rubygem-yard: (lib/yard/core_ext/file.rb) is vulnerable to directory traversal attacks

EPSS

Процентиль: 54%
0.00313
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.

CVSS3: 7.5
nvd
около 8 лет назад

lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.

CVSS3: 7.5
debian
около 8 лет назад

lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not ...

suse-cvrf
больше 7 лет назад

Security update for rubygem-yard

suse-cvrf
больше 7 лет назад

Security update for rubygem-yard

EPSS

Процентиль: 54%
0.00313
Низкий

7.5 High

CVSS3