Ruby on Rails
cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*, +1 more
- < 3.2.18
- >= 4.0, < 4.0.5
- >= 4.1, < 4.1.1
This vulnerability is being actively exploited in the wild.
A directory traversal vulnerability has been identified in Ruby on Rails versions prior to 3.2.18, 4.0.x prior to 4.0.5, and 4.1.x prior to 4.1.1. The vulnerability exists in the implicit-render implementation of Action Pack, specifically within the abstract controller base. When certain route globbing configurations are enabled, remote attackers can read arbitrary files by sending a crafted request that exploits this directory traversal flaw.
Exploitation of this vulnerability allows for arbitrary file read access on the server, potentially leading to the disclosure of sensitive information.
Users are advised to upgrade to Ruby on Rails versions 3.2.18, 4.0.5, or 4.1.1. For Red Hat Subscription Asset Manager users, this update is available through the Red Hat Network.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.