CVE-2016-2097

MEDIUM

Ruby on Rails < 3.2.22.2 and 4.x < 4.1.14.2 - Directory Traversal via Render Method

Title source: llm
STIX 2.1

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0752.

References (8)

Core 8
Core References
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3509
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035122
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/83726

Scores

CVSS v3 5.3
EPSS 0.0191
EPSS Percentile 83.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-22
Status published
Products (28)
rubygems/actionpack 3.0.0 - 3.2.22.2RubyGems
rubygems/actionview 3.0.0 - 3.2.22.2RubyGems
rubyonrails/rails 4.0.0 (4 CPE variants)
rubyonrails/rails 4.0.1 (5 CPE variants)
rubyonrails/rails 4.0.2
rubyonrails/rails 4.0.3
rubyonrails/rails 4.0.4 (2 CPE variants)
rubyonrails/rails 4.0.5
rubyonrails/rails 4.0.6 (4 CPE variants)
rubyonrails/rails 4.0.7
... and 18 more
Published Apr 07, 2016
Tracked Since Feb 18, 2026