Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2026-07240

4 месяца назад

Уязвимость компонента Active Storage программной платформы Ruby on Rails, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260508-73-0003

3 месяца назад

Уязвимость rubygem-activestorage

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-33202

4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 9.1
EPSS: Низкий
redhat логотип

CVE-2026-33202

4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-33202

4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-33202

4 месяца назад

Active Storage allows users to attach cloud and local files in Rails a ...

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-73f9-jhhh-hr5m

4 месяца назад

Rails Active Storage has possible glob injection in its DiskService

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-07240

Уязвимость компонента Active Storage программной платформы Ruby on Rails, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.5
1%
Низкий
4 месяца назад
redos логотип
ROS-20260508-73-0003

Уязвимость rubygem-activestorage

CVSS3: 7.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-33202

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 9.1
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33202

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 6.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33202

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#delete_prefixed` passes blob keys directly to `Dir.glob` without escaping glob metacharacters. If a blob key contains attacker-controlled input or custom-generated keys with glob metacharacters, it may be possible to delete unintended files from the storage directory. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 9.1
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-33202

Active Storage allows users to attach cloud and local files in Rails a ...

CVSS3: 9.1
1%
Низкий
4 месяца назад
github логотип
GHSA-73f9-jhhh-hr5m

Rails Active Storage has possible glob injection in its DiskService

1%
Низкий
4 месяца назад

Уязвимостей на страницу