CVE-2014-0130

HIGH KEV

Ruby on Rails <3.2.18, <4.0.5, <4.1.1 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.

Exploits (1)

nomisec STUB 19 stars
by omarkurt · poc
https://github.com/omarkurt/cve-2014-0130

Scores

CVSS v3 7.5
EPSS 0.4537
EPSS Percentile 97.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation Intel

CISA KEV 2022-03-25
VulnCheck KEV 2022-01-12
InTheWild.io 2022-03-25
ENISA EUVD EUVD-2017-0180

Classification

CWE
CWE-22
Status draft

Affected Products (4)

redhat/subscription_asset_manager < 1.3.0
redhat/enterprise_linux_server
rubyonrails/rails < 3.2.18
rubygems/actionpack < 3.2.18RubyGems

Timeline

Published May 07, 2014
KEV Added Mar 25, 2022
Tracked Since Feb 18, 2026