CVE-2014-125033
rails-cv-app uploaded_files_controller.rb path traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in rails-cv-app. It has been rated as problematic. Affected by this issue is some unknown functionality of the file app/controllers/uploaded_files_controller.rb. The manipulation with the input ../../../etc/passwd leads to path traversal: '../filedir'. The exploit has been disclosed to the public and may be used. The patch is identified as 0d20362af0a5f8a126f67c77833868908484a863. It is recommended to apply a patch to fix this issue. VDB-217178 is the identifier assigned to this vulnerability.
Se encontró una vulnerabilidad en Rails-cv-app. Ha sido calificada como problemática. Una función desconocida del archivo app/controllers/uploaded_files_controller.rb es afectada por este problema. La manipulación con la entrada ../../../etc/passwd conduce al path traversal: '../filedir'. El exploit ha sido divulgado al público y puede utilizarse. El parche se identifica como 0d20362af0a5f8a126f67c77833868908484a863. Se recomienda aplicar un parche para solucionar este problema. VDB-217178 es el identificador asignado a esta vulnerabilidad.
Eine problematische Schwachstelle wurde in rails-cv-app ausgemacht. Betroffen davon ist ein unbekannter Prozess der Datei app/controllers/uploaded_files_controller.rb. Mittels dem Manipulieren mit der Eingabe ../../../etc/passwd mit unbekannten Daten kann eine path traversal: '../filedir'-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung. Der Patch wird als 0d20362af0a5f8a126f67c77833868908484a863 bezeichnet. Als bestmögliche Massnahme wird Patching empfohlen.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-01-02 CVE Reserved
- 2023-01-02 CVE Published
- 2024-07-25 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-24: Path Traversal: '../filedir'
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.217178 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/bertrand-caron/rails-cv-app/commit/0d20362af0a5f8a126f67c77833868908484a863 | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rails-cv-app Project Search vendor "Rails-cv-app Project" | Rails-cv-app Search vendor "Rails-cv-app Project" for product "Rails-cv-app" | < 2014-11-16 Search vendor "Rails-cv-app Project" for product "Rails-cv-app" and version " < 2014-11-16" | - |
Affected
|