VDB
Sign up
HIGH8.6

GHSA-5f9h-9pjv-v6j7

Directory traversal in Rack::Directory app bundled with Rack

Quick fix

GHSA-5f9h-9pjv-v6j7 — rack: upgrade to the fixed version with the command below.

bundle update rack

Details

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/rack
Introduced in: 0Fixed in: 2.1.3
Fixbundle update rack

References