GHSA-4ww3-3rxj-8v6q

Suggest an improvement
Source
https://github.com/advisories/GHSA-4ww3-3rxj-8v6q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-4ww3-3rxj-8v6q/GHSA-4ww3-3rxj-8v6q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4ww3-3rxj-8v6q
Aliases
  • CVE-2011-0449
Published
2017-10-24T18:33:38Z
Modified
2024-11-29T05:42:21Z
Summary
actionpack allows remote attackers to bypass intended access restrictions
Details

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T20:59:33Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

RubyGems / actionpack

Package

Name
actionpack
Purl
pkg:gem/actionpack

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.0.0
Fixed
3.0.4

Affected versions

3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4.rc1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/10/GHSA-4ww3-3rxj-8v6q/GHSA-4ww3-3rxj-8v6q.json"