Skip to content
COOEY

EXPOSURES › CVE-2016-0752

CVE-2016-0752

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2016-0752 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Ruby on Rails directory traversal flaw lets attackers read arbitrary files on vulnerable systems.

A directory traversal vulnerability in Ruby on Rails' Action View component allowed remote attackers to read arbitrary files from the server's filesystem. For DIB organizations, this means unpatched Rails applications could leak sensitive data, violating NIST 800-171 requirements for protecting unclassified information. Organizations must ensure all Ruby on Rails components are patched to the latest secure versions and monitor for exploitation attempts.

Shame score — A known directory traversal vulnerability in a widely used framework that remained unpatched long enough to be listed in CISA's KEV catalog, indicating systemic neglect of critical security updates.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.