Description
rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."
CVSS vector
AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9Integrity: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
4GHSARack Vulnerable to Path Traversal↗2017-10-24 ▶ OSVRack Vulnerable to Path Traversal↗2017-10-24 ▶ CVEListCVE-2013-0262: rack/file↗2013-02-08 ▶ OSVCVE-2013-0262: rack/file↗2013-02-08 ▶ 📋Vendor Advisories
2Red Hatrubygem-rack: Path sanitization information disclosure↗2013-02-08 ▶ DebianCVE-2013-0262: ruby-rack - rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allo...↗2013 ▶ 💬Community
3BugzillaCVE-2013-0262 rubygem-rack: Path sanitization information disclosure↗2013-02-08 ▶ BugzillaCVE-2013-0262 Rubygem Rack: Path sanitization information disclosure [fedora-17]↗2013-02-08 ▶ BugzillaCVE-2013-0262 Rubygem Rack: Path sanitization information disclosure [fedora-18]↗2013-02-08 ▶