peter bassill · operator
$ cve CVE-2016-0752 JSON

CVE-2016-0752 KEV EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 95.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-04-15.

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS95.54% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-22
On CISA KEVyes — remediate by 2022-04-15
Public exploityes
Published2016-02-16
Last modified2026-06-17

CISA KEV

NameRuby on Rails Directory Traversal Vulnerability
Added2022-03-25
Due2022-04-15
Vendor / productRails / Ruby on Rails
Ransomware usenone reported

Affected (6)

VendorProduct
debiandebian linux
opensuseleap
opensuseopensuse
redhatsoftware collections
rubyonrailsrails
suselinux enterprise module for containers

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD