SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2016-0752

Ruby on Rails Directory Traversal Vulnerability

KEVHIGH 7.5EPSS 95.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
95.54% probability · 100th percentile
CISA KEV
Listed 25 March 2022 · due 15 April 2022
Weakness
CWE-22
Affected
rubyonrails/rails · opensuse/leap · opensuse/opensuse · suse/linux enterprise module for containers · debian/debian linux · redhat/software collections
Source
secalert@redhat.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2016-0752

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.