Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41493

Опубликовано: 08 мая 2026
Источник: redhat
CVSS3: 5.3

Описание

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.

A flaw was found in YARD, a Ruby Documentation tool. When using yard server to serve documentation, a path traversal vulnerability allows a remote attacker to access arbitrary files on the host machine through unsanitized HTTP requests. This could lead to unauthorized information disclosure from the server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat 3scale API Management Platform 23scale-amp21/backendNot affected
Red Hat 3scale API Management Platform 23scale-amp21/systemNot affected
Red Hat 3scale API Management Platform 23scale-amp22/backendNot affected
Red Hat 3scale API Management Platform 23scale-amp22/systemOut of support scope
Red Hat 3scale API Management Platform 23scale-amp2/backend-rhel8Out of support scope
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Out of support scope
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Not affected
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel9Not affected
Red Hat Hardened Imagesnghttp2Not affected
Red Hat Hardened ImagesrustNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2468081yard: YARD: Information Disclosure via Path Traversal in yard server

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.

CVSS3: 7.5
nvd
3 месяца назад

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.

CVSS3: 7.5
debian
3 месяца назад

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path tra ...

github
3 месяца назад

yard: Possible arbitrary path traversal and file access via yard server

CVSS3: 5.3
fstec
3 месяца назад

Уязвимость инструмента генерации и хостинга документации YARD языка программирования Ruby, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

5.3 Medium

CVSS3