← All CVEs

CVE-2016-0752

high · 7.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-25Remediation due 2022-04-15

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

7.5
CVSS
95.5%
EPSS (exploit prob.)
100th
EPSS percentile
2016-02-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
rubyonrailsrails< 3.2.22.1
rubyonrailsrails>= 4.0.0, < 4.1.14.1
rubyonrailsrails>= 4.2.0, < 4.2.5.1
rubyonrailsrails5.0.0
opensuseleap42.1
opensuseopensuse13.2
suselinux_enterprise_module_for_containers12
debiandebian_linux8.0
redhatsoftware_collections1.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-0752