MEDIUM
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step
Published Mar 11, 2014
5.0
MEDIUMCVSS 2.0
EPSS 3.02%
Description
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.
Affected products
No data.
AND
OR
- ≤ 1.0.0
- 0.0.1
- 0.0.2
- 0.1.0
- 0.1.1
- 0.1.2
- 0.1.3
- 0.1.4
- 0.1.5
- 0.1.6
- 0.2.0
- 0.3.0
- 0.3.1
- 0.3.2
- 0.3.3
- 0.3.4
- 0.4.0
- 0.5.0
- 0.6.0
- 0.6.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://seclists.org/oss-sec/2013/q4/43 mailing-listx_refsource_MLISTPatch
- http://secunia.com/advisories/55151 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/62891 vdb-entryx_refsource_BID
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87783 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-rprj-g6xc-p5gq Advisory
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/wicked/CVE-2013-4413.yml
- https://github.com/schneems/wicked/commit/fe31bb2533fffc9d098c69ebeb7afc3b80509f53 x_refsource_CONFIRMExploitPatch
- https://nvd.nist.gov/vuln/detail/CVE-2013-4413
- https://web.archive.org/web/20210508170740/http://www.securityfocus.com/bid/62891
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/oss-sec/2013/q4/43 | mailing-listx_refsource_MLISTPatch | |
| http://secunia.com/advisories/55151 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/62891 | vdb-entryx_refsource_BID | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/87783 | vdb-entryx_refsource_XF | |
| https://github.com/advisories/GHSA-rprj-g6xc-p5gq | Advisory | |
| https://github.com/rubysec/ruby-advisory-db/blob/master/gems/wicked/CVE-2013-4413.yml | ||
| https://github.com/schneems/wicked/commit/fe31bb2533fffc9d098c69ebeb7afc3b80509f53 | x_refsource_CONFIRMExploitPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-4413 | ||
| https://web.archive.org/web/20210508170740/http://www.securityfocus.com/bid/62891 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 11, 2014
Updated Aug 6, 2024
Reserved Jun 12, 2013
Link CVE-2013-4413
CISA Vulnrichment
GHSA-RPRJ-G6XC-P5GQ Updated n/a