HIGH7.5
GHSA-gj4p-3wh3-2rmf
Arbitrary file read vulnerability in yard server
Quick fix
GHSA-gj4p-3wh3-2rmf — yard: upgrade to the fixed version with the command below.
bundle update yardDetails
`lib/yard/core_ext/file.rb` in the server in YARD before 0.9.11 does not block relative paths with an initial `../` sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-17042[ADVISORY]
- https://github.com/lsegal/yard/commit/b0217b3e30dc53d057b1682506333335975e62b4[WEB]
- https://github.com/advisories/GHSA-gj4p-3wh3-2rmf[ADVISORY]
- https://github.com/lsegal/yard[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/yard/CVE-2017-17042.yml[WEB]