CVE-2011-2929
The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to render arbitrary views via…
Does this matter?
Lower severity and a low EPSS score (1.81%). Track it; it rarely justifies an emergency change on its own.
Description
The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to render arbitrary views via a crafted URL, related to a "filter skipping vulnerability."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.81% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- rubyonrails/rails · rubyonrails/ruby on rails
- Source
- secalert@redhat.com
References
- http://groups.google.com/group/rubyonrails-security/msg/cbbbba6e4f7eaf61?dmode=source&output=gplainPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065109.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065212.html
- http://weblog.rubyonrails.org/2011/8/16/ann-rails-3-1-0-rc6Patch
- http://www.openwall.com/lists/oss-security/2011/08/17/1Patch
- http://www.openwall.com/lists/oss-security/2011/08/19/11Patch
- http://www.openwall.com/lists/oss-security/2011/08/20/1Patch
- http://www.openwall.com/lists/oss-security/2011/08/22/13Patch
- http://www.openwall.com/lists/oss-security/2011/08/22/14
- http://www.openwall.com/lists/oss-security/2011/08/22/5Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=731432Patch
- https://github.com/rails/rails/commit/5f94b93279f6d0682fafb237c301302c107a9552Patch
- http://groups.google.com/group/rubyonrails-security/msg/cbbbba6e4f7eaf61?dmode=source&output=gplainPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065109.html
- http://lists.fedoraproject.org/pipermail/package-announce/2011-September/065212.html
- http://weblog.rubyonrails.org/2011/8/16/ann-rails-3-1-0-rc6Patch
- http://www.openwall.com/lists/oss-security/2011/08/17/1Patch
- http://www.openwall.com/lists/oss-security/2011/08/19/11Patch
- http://www.openwall.com/lists/oss-security/2011/08/20/1Patch
- http://www.openwall.com/lists/oss-security/2011/08/22/13Patch
- http://www.openwall.com/lists/oss-security/2011/08/22/14
- http://www.openwall.com/lists/oss-security/2011/08/22/5Patch
- https://bugzilla.redhat.com/show_bug.cgi?id=731432Patch
- https://github.com/rails/rails/commit/5f94b93279f6d0682fafb237c301302c107a9552Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.