USN-6731-1: YARD vulnerabilities
It was discovered that YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-17042) It was discovered that yard before 0.9.20 is affected by a path traversal vulnerability, allowing HTTP requests to access arbitrary files under certain conditions. This issue only affected Ubuntu 18.04 LTS. (CVE-2019-1020001) Aviv Keller discovered that the "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. (CVE-2024-27285)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6731-1?
The severity of USN-6731-1 is significant due to the potential for directory traversal attacks that allows attackers to read arbitrary files.
What versions of YARD are affected by USN-6731-1?
USN-6731-1 affects YARD versions prior to 0.9.11 on Ubuntu 16.04 LTS.
How do I fix USN-6731-1?
To fix USN-6731-1, upgrade YARD to version 0.9.28-2ubuntu0.1 or later for Ubuntu 23.10, or to the respective remedied version for earlier Ubuntu releases.
What type of vulnerability is USN-6731-1?
USN-6731-1 identifies a directory traversal vulnerability within YARD that can be exploited to access restricted files.
Is USN-6731-1 only applicable to Ubuntu 16.04 LTS?
Yes, USN-6731-1 specifically affects Ubuntu 16.04 LTS along with other versions across supported Ubuntu distributions but only impacts YARD versions prior to 0.9.11.