CVE-2016-0752

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
16/02/2016
Last modified:
22/10/2025

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* 3.2.22.1 (excluding)
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* 4.0.0 (including) 4.1.14.1 (excluding)
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* 4.2.0 (including) 4.2.5.1 (excluding)
cpe:2.3:a:rubyonrails:rails:5.0.0:beta1:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_module_for_containers:12:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools