Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-0190 | rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals." |
Github GHSA |
GHSA-85r7-w5mv-c849 | Rack Vulnerable to Path Traversal |
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T14:18:09.610Z
Reserved: 2012-12-06T00:00:00.000Z
Link: CVE-2013-0262
No data.
Status : Modified
Published: 2013-02-08T20:55:01.577
Modified: 2026-06-16T23:49:04.787
Link: CVE-2013-0262
OpenCVE Enrichment
No data.
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
EUVD
Github GHSA