Skip to content

Directory traversal vulnerability in Action View in Ruby on Rails #16

Open
@sniffler-app

Description

@sniffler-app

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

Informations

Manifest Path: Gemfile.lock

Please look at dependabot report: https://github.com/swipely/json_controller_generator/security/dependabot/71

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions