CVE-2016-2097

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an applications unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0752.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
2.343

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-2097,CVE-2016-2098 are fixed in Ruby-actionpack 3.2.22.2Windows
Vulnerabilities CVE-2016-2097,CVE-2016-2098 are fixed in Ruby-actionpack 4.1.14.2Windows
Vulnerabilities CVE-2016-2097 are fixed in Ruby-actionview 3.2.22.2Windows
Vulnerabilities CVE-2016-2097 are fixed in Ruby-actionview 4.1.14.2Windows
Vulnerabilities CVE-2016-2097,CVE-2016-2098 are fixed in Ruby-actionpack for Linux 3.2.22.2Linux
Vulnerabilities CVE-2016-2097,CVE-2016-2098 are fixed in Ruby-actionpack for Linux 4.1.14.2Linux
Vulnerabilities CVE-2016-2097 are fixed in Ruby-actionview for Linux 3.2.22.2Linux
Vulnerabilities CVE-2016-2097 are fixed in Ruby-actionview for Linux 4.1.14.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234