Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36438
HistoryJul 22, 2022 - 12:16 p.m.

Directory Traversal

2022-07-2212:16:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.003 Low

EPSS

Percentile

68.6%

tzinfo is vulnerable to Directory Traversal. Whilte Time zone files are loaded with require on demand, it fails to properly validate the time zone identifiers with correct regular expressions, causing a new line character in the identifier. Therefore, an attacker can use TZInfo::Timezone.get to load malicious files and execute within the Ruby process.