CVE-2011-0449: High severity ruby on rails vulnerability
actionpack/lib/actionview/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0449?
CVE-2011-0449 has been classified with a significant severity rating due to its potential to allow unauthorized access.
How do I fix CVE-2011-0449?
To fix CVE-2011-0449, update Ruby on Rails to version 3.0.4 or later.
Which versions of Ruby on Rails are affected by CVE-2011-0449?
CVE-2011-0449 affects Ruby on Rails 3.0.x versions prior to 3.0.4.
What type of attacks could exploit CVE-2011-0449?
CVE-2011-0449 could be exploited by attackers to bypass access restrictions on templates.
Is CVE-2011-0449 related to case sensitivity in filesystems?
Yes, CVE-2011-0449 exploits issues that arise when using case-insensitive filesystems.