CVE-2014-7818
published 2014-11-08CVE-2014-7818: Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before…
PriorityP427medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
3.46%
87.8th percentile
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.
Affected
89 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 0 < 3.2.21 | 3.2.21 |
| actionpack_project | actionpack | >= 3.0.0 < 3.2.21 | 3.2.21 |
| actionpack_project | actionpack | >= 3.0.0 < 3.2.20 | 3.2.20 |
| actionpack_project | actionpack | >= 4.0.0 < 4.0.12 | 4.0.12 |
| actionpack_project | actionpack | >= 4.0.0 < 4.0.11 | 4.0.11 |
| actionpack_project | actionpack | >= 4.1.0 < 4.1.8 | 4.1.8 |
| actionpack_project | actionpack | >= 4.1.0 < 4.1.7 | 4.1.7 |
| actionpack_project | actionpack | >= 4.2.0.beta1 < 4.2.0.beta4 | 4.2.0.beta4 |
| actionpack_project | actionpack | >= 4.2.0.beta1 < 4.2.0.beta3 | 4.2.0.beta3 |
| debian | rails | < rails 2:4.1.8-1 (bookworm) | rails 2:4.1.8-1 (bookworm) |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
ghsa4.3MEDIUM
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Moderate severity vulnerability that affects actionpack
osv·2018-09-17·CVSS 4.3
[MEDIUM] Moderate severity vulnerability that affects actionpack
Moderate severity vulnerability that affects actionpack
Withdrawn, accidental duplicate publish.
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.
GHSA
Moderate severity vulnerability that affects actionpack
ghsa·2018-09-17·CVSS 4.3
[MEDIUM] Moderate severity vulnerability that affects actionpack
Moderate severity vulnerability that affects actionpack
Withdrawn, accidental duplicate publish.
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.
OSV
Directory traversal vulnerability in actionpack
osv·2017-10-24·CVSS 4.3
CVE-2014-7829 [MEDIUM] Directory traversal vulnerability in actionpack
Directory traversal vulnerability in actionpack
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.
OSV
actionpack vulnerable to Path Traversal
osv·2017-10-24
CVE-2014-7818 [MEDIUM] actionpack vulnerable to Path Traversal
actionpack vulnerable to Path Traversal
Directory traversal vulnerability in `actionpack/lib/action_dispatch/middleware/static.rb` in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when `serve_static_assets` is enabled, allows remote attackers to determine the existence of files outside the application root via a `/..%2F` sequence.
GHSA
actionpack vulnerable to Path Traversal
ghsa·2017-10-24
CVE-2014-7818 [MEDIUM] CWE-22 actionpack vulnerable to Path Traversal
actionpack vulnerable to Path Traversal
Directory traversal vulnerability in `actionpack/lib/action_dispatch/middleware/static.rb` in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when `serve_static_assets` is enabled, allows remote attackers to determine the existence of files outside the application root via a `/..%2F` sequence.
GHSA
Directory traversal vulnerability in actionpack
ghsa·2017-10-24·CVSS 4.3
CVE-2014-7829 [MEDIUM] CWE-22 Directory traversal vulnerability in actionpack
Directory traversal vulnerability in actionpack
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.
OSV
CVE-2014-7829: Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static
osv·2014-11-18·CVSS 4.3
CVE-2014-7829 [MEDIUM] CVE-2014-7829: Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.
OSV
CVE-2014-7818: Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static
osv·2014-11-08·CVSS 4.3
CVE-2014-7818 [MEDIUM] CVE-2014-7818: Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.
Red Hat
rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure
vendor_redhat·2014-11-17·CVSS 4.3
CVE-2014-7829 [MEDIUM] CWE-22 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure
rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.
Package: ruby193-rubygem-actionpack (CloudForms Management Engine 5) - Will not fix
Package: ruby193-rubygem-actionpack (Red Hat OpenStack Platform 4) - Will not fix
Package: ror40-rubygem-actionpack (Red Hat Software Collections) - Will not fix
Package: ruby193-rubygem-actionpack (Re
Red Hat
rubygem-actionpack: arbitrary file existence disclosure
vendor_redhat·2014-10-31·CVSS 4.3
CVE-2014-7818 [MEDIUM] CWE-22 rubygem-actionpack: arbitrary file existence disclosure
rubygem-actionpack: arbitrary file existence disclosure
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: ruby193-rubygem-actionpack (CloudForms Management Engine 5) - Will not fix
Packa
Debian
CVE-2014-7818: rails - Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/s...
vendor_debian·2014·CVSS 4.3
CVE-2014-7818 [MEDIUM] CVE-2014-7818: rails - Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/s...
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.
Scope: local
bookworm: resolved (fixed in 2:4.1.8-1)
bullseye: resolved (fixed in 2:4.1.8-1)
forky: resolved (fixed in 2:4.1.8-1)
sid: resolved (fixed in 2:4.1.8-1)
trixie: resolved (fixed in 2:4.1.8-1)
Debian
CVE-2014-7829: rails - Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/s...
vendor_debian·2014·CVSS 4.3
CVE-2014-7829 [MEDIUM] CVE-2014-7829: rails - Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/s...
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.
Scope: local
bookworm: resolved (fixed in 2:4.1.8-1)
bullseye: resolved (fixed in 2:4.1.8-1)
forky: resolved (fixed in 2:4.1.8-1)
sid: resolved (fixed in 2:4.1.8-1)
trixie: resolved (fixed in 2:4.1.8-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7829 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure [fedora-all]
bugzilla·2014-11-18·CVSS 4.3
CVE-2014-7829 [MEDIUM] CVE-2014-7829 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure [fedora-all]
CVE-2014-7829 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2014-7829 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure
bugzilla·2014-11-17·CVSS 4.3
CVE-2014-7829 [MEDIUM] CVE-2014-7829 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure
CVE-2014-7829 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure
The following Ruby on Rails issue was reported:
""
Arbitrary file existence disclosure in Action Pack
There is an information leak vulnerability in Action Pack. This vulnerability
has been assigned the CVE identifier CVE-2014-7829.
Versions Affected: >= 3.0.0
Not affected: <= 3.0.0, 4.2.0.beta4
Fixed Versions: 3.2.21, 4.0.12, 4.1.8
Impact
Specially crafted requests can be used to determine whether a file exists on
the filesystem that is outside the Rails application's root directory. The
files will not be served, but attackers can determine whether or not the file
exists. This vulnerability is very similar to CVE-2014-7818, but the
specially crafted string is slightly different.
Th
Bugzilla
CVE-2014-7818 rubygem-actionpack: arbitrary file existence disclosure [fedora-all]
bugzilla·2014-11-12·CVSS 4.3
CVE-2014-7818 [MEDIUM] CVE-2014-7818 rubygem-actionpack: arbitrary file existence disclosure [fedora-all]
CVE-2014-7818 rubygem-actionpack: arbitrary file existence disclosure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
Bugzilla
CVE-2014-7818 rubygem-actionpack: arbitrary file existence disclosure
bugzilla·2014-11-07·CVSS 4.3
CVE-2014-7818 [MEDIUM] CVE-2014-7818 rubygem-actionpack: arbitrary file existence disclosure
CVE-2014-7818 rubygem-actionpack: arbitrary file existence disclosure
The following Ruby on Rails issue was reported[1]:
""
Arbitrary file existence disclosure in Action Pack
There is an information leak vulnerability in Action Pack. This vulnerability
has been assigned the CVE identifier CVE-2014-7818.
Versions Affected: >= 3.0.0
Not affected: <= 3.0.0
Fixed Versions: 3.2.20, 4.0.11, 4.1.7, 4.2.0.beta3
Impact
Specially crafted requests can be used to determine whether a file exists on the filesystem that is outside the Rails application's root directory. The files will not be served, but attackers can determine whether or not the file exists.
This only impacts Rails applications that enable static file serving at
runtime. For example, the application's production configuration will
http://lists.opensuse.org/opensuse-updates/2014-11/msg00112.htmlhttps://groups.google.com/forum/message/raw?msg=rubyonrails-security/dCp7duBiQgo/v_R_8PFs5IwJhttps://puppet.com/security/cve/cve-2014-7829http://lists.opensuse.org/opensuse-updates/2014-11/msg00112.htmlhttps://groups.google.com/forum/message/raw?msg=rubyonrails-security/dCp7duBiQgo/v_R_8PFs5IwJhttps://puppet.com/security/cve/cve-2014-7829
2014-11-08
Published