Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8161

Опубликовано: 12 мая 2020
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

A directory traversal vulnerability was found in the Rack::Directory app that is bundled with Rack. If certain directories exist in a director managed by the Rack::Directory, this flaw allows an attacker to read the contents of files on the server outside of the root specified in the Rack::Directory initializer. The highest threat from this vulnerability is to confidentiality.

Отчет

Because the following products package the flawed code, but do not use its functionality (Rack::Directory), their impact has been reduced to 'Low':

  • Red Hat CloudForms
  • Red Hat OpenStack Platform 13.0 Operational Tools
  • Red Hat Gluster Storage 3 Red Hat Satellite 6 ships the affected version of RubyGem Rack and is vulnerable to the flaw. However, because attackers require shell access to exploit the vulnerability, Red Hat Product Security has rated this issue as having the security impact of Low for Satellite. A future update might address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-amazon-smartstateFix deferred
CloudForms Management Engine 5cfme-gemsetFix deferred
Red Hat OpenStack Platform 10 (Newton) Operational Toolsrubygem-rackOut of support scope
Red Hat OpenStack Platform 13 (Queens) Operational Toolsrubygem-rackFix deferred
Red Hat Satellite 6tfm-ror52-rubygem-rackAffected
Red Hat Storage 3rubygem-rackAffected
Red Hat Satellite 6.8 for RHEL 7ansible-collection-redhat-satelliteFixedRHSA-2020:436627.10.2020
Red Hat Satellite 6.8 for RHEL 7ansiblerole-foreman_scap_clientFixedRHSA-2020:436627.10.2020
Red Hat Satellite 6.8 for RHEL 7ansiblerole-insights-clientFixedRHSA-2020:436627.10.2020
Red Hat Satellite 6.8 for RHEL 7ansiblerole-satellite-receptor-installerFixedRHSA-2020:436627.10.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1838281rubygem-rack: directory traversal in Rack::Directory

EPSS

Процентиль: 64%
0.00475
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 5 лет назад

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

CVSS3: 8.6
nvd
больше 5 лет назад

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

CVSS3: 8.6
debian
больше 5 лет назад

A directory traversal vulnerability exists in rack < 2.2.0 that allows ...

CVSS3: 8.6
github
больше 5 лет назад

Directory traversal in Rack::Directory app bundled with Rack

CVSS3: 8.6
fstec
больше 5 лет назад

Уязвимость функции check_forbidden из rack/directory.rb модульного интерфейса между веб-серверами и веб-приложениями Rack, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 64%
0.00475
Низкий

5.9 Medium

CVSS3