Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11985
HistoryJan 15, 2019 - 9:10 a.m.

Directory Traversal And Information Disclosure

2019-01-1509:10:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

0.974 High

EPSS

Percentile

99.9%

actionview gem is vulnerable to directory traversal and information disclosure. This vulnerability affects applications which pass user input directly into the β€˜render’ method in an action view controller without verification. Using this vulnerability, attackers can render files from outside the view directory and potentially perform remote code execution. This CVE is handling the issues for all the scenarios which were not covered in CVE-2016-0752.