CVE-2016-0752

Confirmed PUBLISHED

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x...

Ruby on Rails · Action View
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.5 High

At a Glance

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

metasploit ruby cisa
CVE Published
Feb 16, 2016
Exploitation Reported
Mar 25, 2022
CVSS
7.5 High
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • openSUSE-SU-2016:0372 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.html
  • openSUSE-SU-2016:0363 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.html
  • FEDORA-2016-97002ad37b lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2016-Februa...
  • SUSE-SU-2016:1146 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053...
  • FEDORA-2016-fa0dec2360 lists.fedoraproject.org · Vendor Advisory http://lists.fedoraproject.org/pipermail/package-announce/2016-Februa...
Show 7 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.