CVE-2014-0130
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
- Affected products
- Centos, Ruby On Rails
- Redhat Subscription Asset Manager
- ≤ 1.3.0
- Redhat Enterprise Linux Server
- = 6.0
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 53.7% (99th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2014-05-07
CVE-2014-0130 at NVD
6 known exploits for CVE-2014-0130
Proof-of-concept code and exploit modules indexed by Sploitus