CVE-2017-17042

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
28/11/2017
Last modified:
20/04/2025

Description

lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yardoc:yard:*:*:*:*:*:*:*:* 0.9.11 (excluding)