Lucene search

K
githubGitHub Advisory DatabaseGHSA-85R7-W5MV-C849
HistoryOct 24, 2017 - 6:33 p.m.

Rack Vulnerable to Path Traversal

2017-10-2418:33:37
CWE-22
GitHub Advisory Database
github.com
17

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

0.005 Low

EPSS

Percentile

76.5%

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka “symlink path traversals.”

Affected configurations

Vulners
Node
rackrackRange<1.4.5
OR
rackrackRange<1.5.2
CPENameOperatorVersion
racklt1.4.5
racklt1.5.2

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

0.005 Low

EPSS

Percentile

76.5%