You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.
CVE-2011-0449 - High Severity Vulnerability
path: /tmp/git/sample_app/Gemfile.lock
Library home page: http://rubygems.org/gems/rails-3.0.1.gem
Dependency Hierarchy:
actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.
Publish Date: 2011-02-21
URL: CVE-2011-0449
Base Score Metrics not available
Type: Upgrade version
Origin: https://security.gentoo.org/glsa/201412-28
Release Date: 2014-12-14
Fix Resolution: All Ruby on Rails 2.x users should upgrade to the latest version >= rails-2.3.18
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: