lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:yardoc:yard:*:*:*:*:*:*:*:*"
],
"vendor_product": "yardoc:yard",
"extracted_events": [
{
"fixed": "0.9.11"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "0.9.11"
}
]
}
]
}