Описание
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needed | |
| esm-apps-legacy/xenial | released | 0.8.7.6+git20160220-3ubuntu0.1~esm2 |
| esm-apps/bionic | released | 0.9.12-2ubuntu0.1~esm2 |
| esm-apps/focal | released | 0.9.24-1+deb11u1ubuntu0.1~esm1 |
| esm-apps/jammy | released | 0.9.26-1ubuntu0.1+esm1 |
| esm-apps/noble | released | 0.9.36-1ubuntu0.1~esm1 |
| esm-apps/resolute | released | 0.9.38-1ubuntu0.1~esm1 |
| esm-apps/xenial | ignored | end of ESM support, was needed |
| jammy | needed | |
| noble | needed |
Показывать по
7.5 High
CVSS3
Связанные уязвимости
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path tra ...
yard: Possible arbitrary path traversal and file access via yard server
7.5 High
CVSS3