CVE-2016-0752

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an applications unrestricted use of the render method and providing a .. (dot dot) in a pathname.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
92.705

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-7576,CVE-2016-0751,CVE-2016-0752 are fixed in Ruby-actionpack 3.2.22.1Windows
Vulnerabilities CVE-2015-7576,CVE-2016-0751,CVE-2016-0752 are fixed in Ruby-actionpack 4.1.14.1Windows
Vulnerabilities CVE-2015-7581,CVE-2016-0751,CVE-2016-0752 are fixed in Ruby-actionpack 4.2.5.1Windows
Vulnerabilities CVE-2016-0752 are fixed in Ruby-actionview 4.1.14.1Windows
Vulnerabilities CVE-2016-0752 are fixed in Ruby-actionview 4.2.5.1Windows
Vulnerabilities CVE-2015-7576,CVE-2016-0751,CVE-2016-0752 are fixed in Ruby-actionpack for Linux 3.2.22.1Linux
Vulnerabilities CVE-2015-7576,CVE-2016-0751,CVE-2016-0752 are fixed in Ruby-actionpack for Linux 4.1.14.1Linux
Vulnerabilities CVE-2015-7581,CVE-2016-0751,CVE-2016-0752 are fixed in Ruby-actionpack for Linux 4.2.5.1Linux
Vulnerabilities CVE-2016-0752 are fixed in Ruby-actionview for Linux 4.1.14.1Linux
Vulnerabilities CVE-2016-0752 are fixed in Ruby-actionview for Linux 4.2.5.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234