CVE-2017-17042: Path Traversal
Published Nov 28, 2017
·Updated
lib/yard/coreext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
Affected Software
4 affected componentsFixes available
Yardoc Yard<0.9.11
debian/yard
0.9.16-10.9.16-1+deb10u10.9.24-10.9.24-1+deb11u10.9.28-20.9.28-2+deb12u20.9.36-1
ubuntu/yard<0.9.12-1
0.9.12-1
ubuntu/yard<0.8.7.6+
0.8.7.6+
Remediation
Event History
Nov 28, 2017
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Apr 15, 2024
Data Sourced
via Launchpad·10:56 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17042?
CVE-2017-17042 has been classified with a moderate severity due to its ability to allow directory traversal attacks.
2
How do I fix CVE-2017-17042?
To fix CVE-2017-17042, upgrade YARD to version 0.9.11 or later.
3
What systems are affected by CVE-2017-17042?
CVE-2017-17042 affects YARD versions prior to 0.9.11.
4
What type of attack does CVE-2017-17042 enable?
CVE-2017-17042 enables directory traversal attacks that can allow unauthorized file access.
5
Is CVE-2017-17042 fixed in the latest version of YARD?
Yes, CVE-2017-17042 is resolved in YARD versions 0.9.11 and later.