PT-2019-11617 · Yard+3 · Yard+3
Cuongmx
·
Published
2019-07-02
·
Updated
2024-04-15
·
CVE-2019-1020001
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
yard versions prior to 0.9.20
Description:
A path traversal issue was discovered in yard when using
yard server to serve documentation, allowing unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions.Recommendations:
For versions prior to 0.9.20, upgrade to YARD v0.9.20 immediately if you are relying on yard server to host documentation in any untrusted environments.
As a temporary workaround for users who cannot upgrade, consider performing path sanitization of HTTP requests at your webserver level, such as using WEBrick via
yard server -s webrick, or applying certain rules in your webserver configuration to minimize the risk of exploitation.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Ubuntu
Yard