Back

HIGH

rubygem-rack: directory traversal in Rack::Directory

Published Jul 2, 2020

Description

A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.

Affected products

Remediation

Red Hat statement

Because the following products package the flawed code, but do not use its functionality (Rack::Directory), their impact has been reduced to 'Low': * Red Hat CloudForms * Red Hat OpenStack Platform 13.0 Operational Tools * Red Hat Gluster Storage 3 Red Hat Satellite 6 ships the affected version of RubyGem Rack and is vulnerable to the flaw. However, because attackers require shell access to exploit the vulnerability, Red Hat Product Security has rated this issue as having the security impact of Low for Satellite. A future update might address this issue.

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Jul 2, 2020
Updated Aug 4, 2024
Reserved Jan 28, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 12, 2020
ENISA EUVD
Assigner hackerone
Published Jul 2, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-0537 GHSA-5F9H-9PJV-V6J7