Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-2929

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2011-2929
Last Modified 06 Jul 2012 12:00:00
Published 29 Aug 2011 02:55:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2011-2929

Summary

The template selection functionality in actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.10 and 3.1.x before 3.1.0.rc6 does not properly handle glob characters, which allows remote attackers to render arbitrary views via a crafted URL, related to a "filter skipping vulnerability."

Vulnerable Systems

Application

  • Ruby On Rails 3.0.0

  • Ruby On Rails 3.0.1

  • Ruby On Rails 3.0.2

  • Ruby On Rails 3.0.3

  • Ruby On Rails 3.0.4

  • Ruby On Rails 3.0.5

  • Ruby On Rails 3.0.6

  • Ruby On Rails 3.0.7

  • Ruby On Rails 3.0.8

  • Ruby On Rails 3.0.9

  • Ruby On Rails 3.1.0

  • Rubyonrails Ruby On Rails 3.0.0

  • Rubyonrails Ruby On Rails 3.0.1

  • Rubyonrails Ruby On Rails 3.0.10

  • Rubyonrails Ruby On Rails 3.0.2

  • Rubyonrails Ruby On Rails 3.0.3

  • Rubyonrails Ruby On Rails 3.0.4

  • Rubyonrails Ruby On Rails 3.0.5

  • Rubyonrails Ruby On Rails 3.0.6

  • Rubyonrails Ruby On Rails 3.0.7

  • Rubyonrails Ruby On Rails 3.0.8

  • Rubyonrails Ruby On Rails 3.0.9

  • Rubyonrails Ruby On Rails 3.1.0


References

CONFIRM - https://github.com/rails/rails/commit/5f94b93279f6d0682fafb237c301302c107a9552

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=731432

MLIST - [oss-security] 20110822 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110820 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110819 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110817 CVE request: ruby on rails flaws (4)

CONFIRM - http://weblog.rubyonrails.org/2011/8/16/ann-rails-3-1-0-rc6

MLIST - [rubyonrails-security] 20110816 Filter Skipping Vulnerability in Ruby on Rails 3.0

FEDORA - FEDORA-2011-11386

FEDORA - FEDORA-2011-11572


Last Updated: 27 May 2016 10:54:50