Skip to content
COOEY

EXPOSURES › CVE-2014-0130

CVE-2014-0130

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2014-0130 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Ruby on Rails directory traversal flaw allowed attackers to read arbitrary files via crafted requests.

A directory traversal vulnerability in Ruby on Rails' implicit-render implementation enabled remote attackers to read arbitrary files on affected systems. DIB organizations must ensure their Ruby on Rails applications are patched to prevent information disclosure and potential lateral movement. This failure highlights the risk of relying on unpatched, widely-used frameworks without rigorous supply-chain validation.

Shame score — A known directory traversal vulnerability in a widely-used framework was actively exploited in the wild, indicating a failure to patch critical flaws in time.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers to read arbitrary files via a crafted request.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.