← Back to CVE List
Vulnerability Intelligence Report
Ruby on Rails Directory Traversal Vulnerability

CVE-2016-0752

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:95.54%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Affected Products & Versions

Vendor Product Affected Versions
rubyonrails rails 5.0.0
opensuse leap 42.1
opensuse opensuse 13.2
suse linux_enterprise_module_for_containers 12
debian debian_linux 8.0
redhat software_collections 1.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
95.537%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityRed Hat, Inc. · Vendor · USA
Reserved2015-12-16T00:00:00
Published2016-02-16T02:00:00
Patch Date2016-01-25
Last Updated2025-10-21T23:55:55

LINK COPIED TO CLIPBOARD