CVE-2014-0130 is a directory traversal vulnerability in Ruby on Rails versions before 3.2.18, 4.0.5, and 4.1.1, specifically affecting the implicit-render implementation when certain route globbing configurations are enabled. This flaw allows remote attackers to read arbitrary files, impacting products like Red Hat Enterprise Linux and Ruby on Rails itself. With a CVSS score of 7.5 (High), it presents a low-complexity network attack vector with high confidentiality impact. This vulnerability is actively exploited, listed in the KEV catalog, and has garnered significant community discussion and media coverage, despite no public exploit code in Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.0CPE matchmatch criteria | cpe:2.3:a:redhat:subscription_asset_manager:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:* | ||
< 3.2.18CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.5CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* | ||
>= 4.1.0, < 4.1.1CPE matchmatch criteria | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.