Количество 10
Количество 10
GHSA-h2jq-g4cq-5ppq
Rack::Static prefix matching can expose unintended files under the static root
CVE-2026-34785
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.
CVE-2026-34785
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.
CVE-2026-34785
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6.
CVE-2026-34785
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ...
BDU:2026-07735
Уязвимость модульного интерфейса веб-сервера Rack языка программирования Ruby, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
ROS-20260513-73-0008
Уязвимость rubygem-rack
SUSE-SU-2026:2487-1
Security update for rmt-server
SUSE-SU-2026:1964-1
Security update for rmt-server
SUSE-SU-2026:1745-1
Security update for rmt-server
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-h2jq-g4cq-5ppq Rack::Static prefix matching can expose unintended files under the static root | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34785 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34785 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34785 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Static determines whether a request should be served as a static file using a simple string prefix check. When configured with URL prefixes such as "/css", it matches any request path that begins with that string, including unrelated paths such as "/css-config.env" or "/css-backup.sql". As a result, files under the static root whose names merely share the configured prefix may be served unintentionally, leading to information disclosure. This issue has been patched in versions 2.2.23, 3.1.21, and 3.2.6. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-34785 Rack is a modular Ruby web server interface. Prior to versions 2.2.23, ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
BDU:2026-07735 Уязвимость модульного интерфейса веб-сервера Rack языка программирования Ruby, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
ROS-20260513-73-0008 Уязвимость rubygem-rack | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
SUSE-SU-2026:2487-1 Security update for rmt-server | около 1 месяца назад | |||
SUSE-SU-2026:1964-1 Security update for rmt-server | 3 месяца назад | |||
SUSE-SU-2026:1745-1 Security update for rmt-server | 3 месяца назад |
Уязвимостей на страницу