Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

github логотип

GHSA-mxw3-3hh2-x2mh

6 месяцев назад

Rack has a Directory Traversal via Rack:Directory

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-22860

6 месяцев назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-22860

6 месяцев назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-22860

6 месяцев назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-22860

6 месяцев назад

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-07219

6 месяцев назад

Уязвимость модульного интерфейса между веб-серверами и веб-приложениями Rack, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260417-73-0028

4 месяца назад

Уязвимость rubygem-rack

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mxw3-3hh2-x2mh

Rack has a Directory Traversal via Rack:Directory

CVSS3: 7.5
1%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2026-22860

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-22860

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-22860

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, 3.1.20, and 3.2.5, `Rack::Directory`’s path check used a string prefix match on the expanded path. A request like `/../root_example/` can escape the configured root if the target path starts with the root string, allowing directory listing outside the intended root. Versions 2.2.22, 3.1.20, and 3.2.5 fix the issue.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
debian логотип
CVE-2026-22860

Rack is a modular Ruby web server interface. Prior to versions 2.2.22, ...

CVSS3: 7.5
1%
Низкий
6 месяцев назад
fstec логотип
BDU:2026-07219

Уязвимость модульного интерфейса между веб-серверами и веб-приложениями Rack, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redos логотип
ROS-20260417-73-0028

Уязвимость rubygem-rack

CVSS3: 7.5
1%
Низкий
4 месяца назад

Уязвимостей на страницу