Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-22860

Опубликовано: 18 фев. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, Rack::Directory’s path check used a string prefix match on the expanded path. A request like /../root_example/ can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

РелизСтатусПримечание
devel

released

3.2.4-1ubuntu1
esm-apps/bionic

ignored

changes too intrusive
esm-apps/focal

released

2.0.7-2ubuntu0.1+esm9
esm-apps/jammy

released

2.1.4-5ubuntu1.2+esm2
esm-apps/xenial

ignored

changes too intrusive
esm-infra-legacy/trusty

ignored

changes too intrusive
jammy

needed

noble

released

2.2.7-1ubuntu0.6
questing

released

3.1.16-0.1ubuntu0.2
upstream

released

3.2.5,3.1.20,2.2.22

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 1 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

CVSS3: 7.5
nvd
около 1 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

CVSS3: 7.5
debian
около 1 месяца назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, ...

CVSS3: 7.5
github
около 1 месяца назад

Rack has a Directory Traversal via Rack:Directory

7.5 High

CVSS3