Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2026-33195

4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-33195

4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2026-33195

4 месяца назад

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-33195

4 месяца назад

Active Storage allows users to attach cloud and local files in Rails a ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-9xrj-h377-fr87

4 месяца назад

Rails Active Storage has possible Path Traversal in DiskService

EPSS: Низкий
fstec логотип

BDU:2026-07234

4 месяца назад

Уязвимость библиотеки для подключения облачных и локальных файлов к приложениям Rails Active Storage, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
EPSS: Низкий
redos логотип

ROS-20260508-73-0005

3 месяца назад

Уязвимость rubygem-activestorage

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-33195

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 9.8
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-33195

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 8.1
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-33195

Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.2.3.1, Active Storage's `DiskService#path_for` does not validate that the resolved filesystem path remains within the storage root directory. If a blob key containing path traversal sequences (e.g. `../`) is used, it could allow reading, writing, or deleting arbitrary files on the server. Blob keys are expected to be trusted strings, but some applications could be passing user input as keys and would be affected. Versions 8.1.2.1, 8.0.4.1, and 7.2.3.1 contain a patch.

CVSS3: 9.8
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-33195

Active Storage allows users to attach cloud and local files in Rails a ...

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-9xrj-h377-fr87

Rails Active Storage has possible Path Traversal in DiskService

1%
Низкий
4 месяца назад
fstec логотип
BDU:2026-07234

Уязвимость библиотеки для подключения облачных и локальных файлов к приложениям Rails Active Storage, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 9.1
1%
Низкий
4 месяца назад
redos логотип
ROS-20260508-73-0005

Уязвимость rubygem-activestorage

CVSS3: 9.1
1%
Низкий
3 месяца назад

Уязвимостей на страницу