CVE-2016-0752
Ruby on Rails Directory Traversal Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 95.54% probability · 100th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-22
- Affected
- rubyonrails/rails · opensuse/leap · opensuse/opensuse · suse/linux enterprise module for containers · debian/debian linux · redhat/software collections
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-0752
References
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178044.htmlPermissions Required
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178069.htmlPermissions Required
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0296.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3464Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/25/13Exploit, Mailing List
- http://www.securityfocus.com/bid/81801Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034816Broken Link, Third Party Advisory, VDB Entry
- https://groups.google.com/forum/message/raw?msg=ruby-security-ann/335P1DcLG00/JXcBnTtZEgAJBroken Link
- https://www.exploit-db.com/exploits/40561/Exploit, Third Party Advisory, VDB Entry
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178044.htmlPermissions Required
- http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178069.htmlPermissions Required
- http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-0296.htmlThird Party Advisory
- http://www.debian.org/security/2016/dsa-3464Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/01/25/13Exploit, Mailing List
- http://www.securityfocus.com/bid/81801Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1034816Broken Link, Third Party Advisory, VDB Entry
- https://groups.google.com/forum/message/raw?msg=ruby-security-ann/335P1DcLG00/JXcBnTtZEgAJBroken Link
- https://www.exploit-db.com/exploits/40561/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-0752US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.