Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ruby-actionmailer.Upgrade ruby-redmine-actionmailer. | Aug 30, 2017 | Nov 8, 2014 |
| Debian | — | Upgrade rails | Jul 30, 2024 | Nov 8, 2014 |
| Ruby_on_rails | — | Upgrade to the latest version of Ruby on Rails | Jan 3, 2020 | Nov 8, 2014 |
| Suse | — | Upgrade rubygem-actionpack-3_2Upgrade ruby2.5-rubygem-actionpack-5_1 | Dec 18, 2015 | Nov 8, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub