PT-2016-1280 · Ruby+1 · Ruby On Rails+1

John Poulin

·

Published

2016-01-31

·

Updated

2025-04-02

·

CVE-2016-0752

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions prior to 3.2.22.1 Ruby on Rails versions 4.0.x through 4.1.14 Ruby on Rails versions 4.2.x through 4.2.5 Ruby on Rails versions 5.x through 5.0.0.beta1.1
Description The issue is related to a directory traversal vulnerability in the Action View component of Ruby on Rails. This vulnerability can be exploited by remote attackers to read arbitrary files by providing a .. (dot dot) in a pathname, leveraging an application's unrestricted use of the render method.
Recommendations For Ruby on Rails versions prior to 3.2.22.1, update to version 3.2.22.1 or later. For Ruby on Rails versions 4.0.x through 4.1.14, update to version 4.1.14.1 or later. For Ruby on Rails versions 4.2.x through 4.2.5, update to version 4.2.5.1 or later. For Ruby on Rails versions 5.x through 5.0.0.beta1.1, update to version 5.0.0.beta1.1 or later. As a temporary workaround, consider restricting the use of the render method to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2016-00577
CVE-2016-0752
DLA-604-1
DSA-3464-1
DSA-3509-1
GHSA-6834-R92F-JJ42
GHSA-XRR4-P6FQ-HJG7
RHSA-2016:0296
RHSA-2016:0454
RHSA-2016:0455
SUSE-SU-2016:0456-1
SUSE-SU-2016:0457-1
SUSE-SU-2016:0599-1
SUSE-SU-2016:0618-1
SUSE-SU-2016:0858-1
SUSE-SU-2016:1146-1
SUSE-SU-2016_0618-1
SUSE-SU-2017:0475-1

Affected Products

Ruby On Rails
Suse