Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11329
HistoryJan 15, 2019 - 9:00 a.m.

Arbitrary File Access Using A Symlink Attack

2019-01-1509:00:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.005 Low

EPSS

Percentile

76.5%

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka ‘symlink path traversals.’