PT-2011-2352 · Ruby+1 · Ruby On Rails+1

Published

2011-02-21

·

Updated

2019-08-08

·

CVE-2011-0449

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions 3.0.x through 3.0.3
Description The issue allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters, when a case-insensitive filesystem is used. This occurs due to improper implementation of filters associated with the list of available templates in the actionpack/lib/action view/template/resolver.rb file.
Recommendations For Ruby on Rails versions 3.0.x through 3.0.3, update to version 3.0.4 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-0449
GHSA-4WW3-3RXJ-8V6Q

Affected Products

Ruby On Rails
Suse