First published: Tue Mar 11 2014(Updated: )
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneems Wicked | <=1.0.0 | |
Schneems Wicked | =0.0.1 | |
Schneems Wicked | =0.0.2 | |
Schneems Wicked | =0.1.0 | |
Schneems Wicked | =0.1.1 | |
Schneems Wicked | =0.1.2 | |
Schneems Wicked | =0.1.3 | |
Schneems Wicked | =0.1.4 | |
Schneems Wicked | =0.1.5 | |
Schneems Wicked | =0.1.6 | |
Schneems Wicked | =0.2.0 | |
Schneems Wicked | =0.3.0 | |
Schneems Wicked | =0.3.1 | |
Schneems Wicked | =0.3.2 | |
Schneems Wicked | =0.3.3 | |
Schneems Wicked | =0.3.4 | |
Schneems Wicked | =0.4.0 | |
Schneems Wicked | =0.5.0 | |
Schneems Wicked | =0.6.0 | |
Schneems Wicked | =0.6.1 | |
Ruby-lang Ruby |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.