CVE-2011-2929Improper Input Validation in Project Actionpack

Severity
5.0MEDIUMNVD
EPSS
0.8%
top 25.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 29
Latest updateOct 24

Description

The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to render arbitrary views via a crafted URL, related to a "filter skipping vulnerability."

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDrubyonrails/rails12 versions+11
RubyGemsactionpack_project/actionpack3.0.03.0.10

Patches

🔴Vulnerability Details

3
GHSA
actionpack Improper Input Validation vulnerability2017-10-24
OSV
actionpack Improper Input Validation vulnerability2017-10-24
CVEList
CVE-2011-2929: The template selection functionality in actionpack/lib/action_view/template/resolver2011-08-29

📋Vendor Advisories

1
Debian
CVE-2011-2929: rails - The template selection functionality in actionpack/lib/action_view/template/reso...2011

💬Community

1
Bugzilla
CVE-2011-2929 rubygem-actionpack: filter skipping vulnerability (Ruby on Rails)2011-08-17
CVE-2011-2929 — Improper Input Validation | cvebase