Lack of data validation - Path Traversal In rails
Description
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's filesystem to be exposed.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 12 | 2:5.2.2.1+dfsg-1 | ||
debian 13 | 2:5.2.2.1+dfsg-1 | ||
debian 14 | 2:5.2.2.1+dfsg-1 | ||
rubygems | 4.2.11.1, 5.0.7.2, 5.1.6.2, 5.2.2.1 | ||
rubygems | 5.2.2.1, 4.2.11.1, 5.1.6.2, 5.0.7.2 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16.