EXPOSURES › CVE-2016-0752
CVE-2016-0752
HIGH ⌖ ON CISA KEV · EXPLOITEDRuby on Rails directory traversal flaw lets attackers read arbitrary files on vulnerable systems.
A directory traversal vulnerability in Ruby on Rails' Action View component allowed remote attackers to read arbitrary files from the server's filesystem. For DIB organizations, this means unpatched Rails applications could leak sensitive data, violating NIST 800-171 requirements for protecting unclassified information. Organizations must ensure all Ruby on Rails components are patched to the latest secure versions and monitor for exploitation attempts.
Shame score — A known directory traversal vulnerability in a widely used framework that remained unpatched long enough to be listed in CISA's KEV catalog, indicating systemic neglect of critical security updates.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.