Количество 7
Количество 7
CVE-2026-41493
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
CVE-2026-41493
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
CVE-2026-41493
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
CVE-2026-41493
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path tra ...
GHSA-3jfp-46x4-xgfj
yard: Possible arbitrary path traversal and file access via yard server
BDU:2026-10465
Уязвимость инструмента генерации и хостинга документации YARD языка программирования Ruby, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260707-73-0010
Уязвимость rubygem-yard
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41493 YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41493 YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-41493 YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-41493 YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path tra ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-3jfp-46x4-xgfj yard: Possible arbitrary path traversal and file access via yard server | 0% Низкий | 3 месяца назад | ||
BDU:2026-10465 Уязвимость инструмента генерации и хостинга документации YARD языка программирования Ruby, связанная с неверным ограничением имени пути к каталогу, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
ROS-20260707-73-0010 Уязвимость rubygem-yard | CVSS3: 5.3 | 0% Низкий | 24 дня назад |
Уязвимостей на страницу