First published: Mon Apr 15 2024(Updated: )
It was discovered that YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-17042) It was discovered that yard before 0.9.20 is affected by a path traversal vulnerability, allowing HTTP requests to access arbitrary files under certain conditions. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1020001) Aviv Keller discovered that the "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. (CVE-2024-27285)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/yard | <0.9.28-2ubuntu0.1 | 0.9.28-2ubuntu0.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/yard | <0.9.26-1ubuntu0.1 | 0.9.26-1ubuntu0.1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/yard | <0.9.24-1+deb11u1build0.20.04.1 | 0.9.24-1+deb11u1build0.20.04.1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/yard | <0.9.12-2ubuntu0.1~esm1 | 0.9.12-2ubuntu0.1~esm1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/yard | <0.8.7.6+git20160220-3ubuntu0.1~esm1 | 0.8.7.6+git20160220-3ubuntu0.1~esm1 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-6731-1 is significant due to the potential for directory traversal attacks that allows attackers to read arbitrary files.
USN-6731-1 affects YARD versions prior to 0.9.11 on Ubuntu 16.04 LTS.
To fix USN-6731-1, upgrade YARD to version 0.9.28-2ubuntu0.1 or later for Ubuntu 23.10, or to the respective remedied version for earlier Ubuntu releases.
USN-6731-1 identifies a directory traversal vulnerability within YARD that can be exploited to access restricted files.
Yes, USN-6731-1 specifically affects Ubuntu 16.04 LTS along with other versions across supported Ubuntu distributions but only impacts YARD versions prior to 0.9.11.