Vulnerability Intelligence Report
Ruby on Rails Directory Traversal Vulnerability
CVE-2016-0752
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
CISA KEV
SSVC: Active Exploitation
Automatable
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:95.54%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-22 ↗CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| rubyonrails | rails | 5.0.0 |
| opensuse | leap | 42.1 |
| opensuse | opensuse | 13.2 |
| suse | linux_enterprise_module_for_containers | 12 |
| debian | debian_linux | 8.0 |
| redhat | software_collections | 1.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2015-12-16T00:00:00 |
| Published | 2016-02-16T02:00:00 |
| Patch Date | 2016-01-25 |
| Last Updated | 2025-10-21T23:55:55 |
Community Chatter & Buzz