VDB
KO
MEDIUM

GHSA-29gr-w57f-rpfw

actionpack vulnerable to Path Traversal

Details

Directory traversal vulnerability in `actionpack/lib/action_dispatch/middleware/static.rb` in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when `serve_static_assets` is enabled, allows remote attackers to determine the existence of files outside the application root via a `/..%2F` sequence.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems / actionpack
Introduced in: 3.0.0 Fixed in: 3.2.20
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 4.0.0 Fixed in: 4.0.11
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 4.1.0 Fixed in: 4.1.7
Fix bundle update actionpack
RubyGems / actionpack
Introduced in: 4.2.0.beta1 Fixed in: 4.2.0.beta3
Fix bundle update actionpack

References