PT-2019-11617 · Yard+3 · Yard+3

·

CVE-2019-1020001

·

Published

2019-07-02

·

Updated

2024-04-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: yard versions prior to 0.9.20
Description: A path traversal issue was discovered in yard when using yard server to serve documentation, allowing unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions.
Recommendations: For versions prior to 0.9.20, upgrade to YARD v0.9.20 immediately if you are relying on yard server to host documentation in any untrusted environments. As a temporary workaround for users who cannot upgrade, consider performing path sanitization of HTTP requests at your webserver level, such as using WEBrick via yard server -s webrick, or applying certain rules in your webserver configuration to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1020001
DLA-3753-1
GHSA-XFHH-RX56-RXCR
OESA-2021-1289
USN-6731-1

Affected Products

Astra Linux
Linuxmint
Ubuntu
Yard