VDB
CVE-2016-0752
CVE-2016-0752
REJECTED
KEV
CVSS 7.5 HIGH
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
EPSS 95.54% · 99.9th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
95.54%
99.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | rails | *, *, 0 |
Timeline
- CVE Published
- Mar 1, 2016 PoC Published
- Mar 1, 2016 PoC Published
- Oct 15, 2016 PoC Published
- Dec 17, 2019 VulnCheck KEV Exploitation
- Dec 1, 2020 VulnCheck KEV Exploitation
- Jan 12, 2022 VulnCheck KEV Exploitation
- Feb 4, 2022 EPSS Score
- Mar 25, 2022 CISA KEV Added
- Mar 25, 2022 VulnCheck KEV Exploitation
- Mar 29, 2022 EPSS Score
- May 11, 2022 VulnCheck KEV Exploitation
References
- https://ubuntu.com/security/CVE-2016-0752 third-party-advisory
- https://marc.info/?l=oss-security&m=145375068928706&w=2 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2016-0752 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog third-party-advisory