QID 995363
Date Published: 2023-09-25
QID 995363: Rubygems (Rubygems) Security Update for mongrel (GHSA-m7r6-43v2-49vf)
Directory traversal vulnerability in DirHandler (lib/mongrel/handlers.rb) in Mongrel 1.0.4 (1.0.3 and prior are not affected) and 1.1.x before 1.1.3 allows remote attackers to read arbitrary files via an HTTP request containing double-encoded sequences (.%252e).
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-m7r6-43v2-49vf for updates and patch information.
Vendor References
- GHSA-m7r6-43v2-49vf -
github.com/advisories/GHSA-m7r6-43v2-49vf
CVEs related to QID 995363
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m7r6-43v2-49vf | mongrel |
|