Junglewise Threat Intelligence

CVE-2016-0752: Ruby on Rails Directory Traversal Vulnerability

CVE-2016-0752 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2022-03-25

Technologies: Rails Ruby on Rails. Vendors: Rails, Ruby on Rails.

Executive brief

A directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files. The flaw is triggered by an application's unrestricted use of the render method when processing pathnames containing dot-dot (..) sequences.

Affected products

  • Ruby on Rails Rails (Action View) before 3.2.22.1, 4.0.x, 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1

Timeline

  • 2016-01-25: disclosed: Initial public disclosure via oss-security mailing list.
  • 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-03-25: exploited: Confirmed as exploited in the wild.

Related threats