FlawAtlas
Search the atlas
CVE-2016-0752 High

Confirmed as exploited

CVE-2016-0752

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

Exploit probability 95.5%
Published February 16, 2016
Required by April 15, 2022
Last source change August 7, 2026

01 / ACTION

Required action

Apply updates per vendor instructions.

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

53 explicit affected versions

RubyGems actionpack

250 explicit affected versions

RubyGems actionview

48 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities CVE-2016-0752

Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.

View original source
Open Source Vulnerabilities GHSA-xrr4-p6fq-hjg7

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a `..` (dot dot) in a pathname.

View original source
Open Source Vulnerabilities CVE-2016-0752

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

View original source

05 / REFERENCES

Further evidence