Junglewise Threat Intelligence

CVE-2014-0130: actionpack Path Traversal vulnerability

CVE-2014-0130 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2017-10-24

Technologies: Rails Ruby on Rails, Ruby on Rails Rails. Vendors: Rails, Red Hat, Ruby on Rails.

Executive brief

A directory traversal vulnerability exists in the implicit-render implementation of Ruby on Rails. When certain route globbing configurations are enabled, remote attackers can read arbitrary files via a crafted request.

Affected products

  • Ruby on Rails Rails before 3.2.18, 4.0.x before 4.0.5, 4.1.x before 4.1.1
  • Red Hat Subscription Asset Manager up to 1.3.0

Timeline

  • 2014-05-06: disclosed: Initial disclosure date based on external references (BID 67244)
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats