Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-0449

Опубликовано: 21 фев. 2011
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 7.5

Описание

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.

РелизСтатусПримечание
dapper

not-affected

3.0.x only
devel

not-affected

3.0.x only
hardy

not-affected

3.0.x only
karmic

not-affected

3.0.x only
lucid

not-affected

3.0.x only
maverick

not-affected

3.0.x only
upstream

released

3.0.4

Показывать по

Ссылки на источники

EPSS

Процентиль: 67%
0.00555
Низкий

7.5 High

CVSS2

Связанные уязвимости

nvd
почти 15 лет назад

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.

debian
почти 15 лет назад

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x ...

github
около 8 лет назад

actionpack allows remote attackers to bypass intended access restrictions

EPSS

Процентиль: 67%
0.00555
Низкий

7.5 High

CVSS2