Lucene search

K
cvelistRedhatCVELIST:CVE-2011-2929
HistoryAug 29, 2011 - 6:00 p.m.

CVE-2011-2929

2011-08-2918:00:00
redhat
www.cve.org

6.3 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.3%

The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to render arbitrary views via a crafted URL, related to a “filter skipping vulnerability.”

6.3 Medium

AI Score

Confidence

Low

0.008 Low

EPSS

Percentile

81.3%