CyberSec.Space Logo
Back to CVE Browser

CVE-2016-0752

Known Exploited (CISA KEV)HIGH
7.5
CVSS Severity Score
EPSS Score28.6600%
EPSS Percentile89.59th
PublishedFeb 16, 2016
Last ModifiedApr 22, 2026

Vulnerability Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

Affected Platforms (CPE)

πŸ“¦
Rubyonrails

Rails

< 3.2.22.1
πŸ“¦
Rubyonrails

Rails

>= 4.0.0 and < 4.1.14.1
πŸ“¦
Rubyonrails

Rails

>= 4.2.0 and < 4.2.5.1
πŸ“¦
Rubyonrails

Rails

= 5.0.0
πŸ’»
Opensuse

Leap

= 42.1
πŸ’»
Opensuse

Opensuse

= 13.2
πŸ’»
Suse

Linux Enterprise Module For Containers

= 12
πŸ’»
Debian

Debian Linux

= 8.0
πŸ“¦
Redhat

Software Collections

= 1.0

References & Advisories

Related Vulnerabilities

CVE-2016-0752 Detail & Impact Analysis | CVSS 7.5 (HIGH) | Cyber-Sec.Space | Cyber-Sec.Space