Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19717
HistoryMay 16, 2019 - 3:22 a.m.

Directory Traversal

2019-05-1603:22:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.002 Low

EPSS

Percentile

59.3%

Ruby is vulnerable to directory traversal vulnerability. This is because the methods from the Dir class does not properly handle strings containing the NULL byte. An attacker could inject NULL bytes in a path causing a directory traversal condition.