CVE-2014-7829 — Path Traversal in Project Actionpack
Severity
5.0MEDIUMNVD
CNA4.3GHSA4.3OSV4.3
EPSS
0.3%
top 49.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 18
Latest updateMar 29
Description
Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.21, 4.0.x before 4.0.12, 4.1.x before 4.1.8, and 4.2.x before 4.2.0.beta4, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via vectors involving a \ (backslash) character, a similar issue to CVE-2014-7818.
CVSS vector
AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9
Affected Packages5 packages
🔴Vulnerability Details
4📋Vendor Advisories
2💬Community
3HackerOne▶
reports.breadcrumb.com is vulnerable for Arbitrary file existence disclosur CVE-2014-7829↗2018-03-29
Bugzilla▶
CVE-2014-7829 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure [fedora-all]↗2014-11-18
Bugzilla▶
CVE-2014-7829 rubygem-actionpack: incomplete fix for CVE-2014-7818, arbitrary file existence disclosure↗2014-11-17