Back

HIGH KEV

rubygem-actionpack: directory traversal flaw in Action View

Published Feb 16, 2016 ·Due Apr 15, 2022

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

Affected products

Remediation

Red Hat mitigation

Avoid passing untrusted input to render method, or verify the input using whitelist before passing it to the render method: ``` def index render verify_template(params[:id]) end private def verify_template(name) # add verification logic particular to your application here end ```

Metrics

Weaknesses (1)

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 16, 2016
Updated Oct 21, 2025
Reserved Dec 16, 2015
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 25, 2016
GHSA-XRR4-P6FQ-HJG7