← Back to browse · API

CVE-2016-0752

Severity
HIGH
CVSS
7.5
EPSS
0.95537
Risk score
58.44
CISA KEV
Yes
PoC
No
Published
2016-02-16
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2017-0333, GHSA-XRR4-P6FQ-HJG7
Products
Rails:Ruby on Rails, n/a:n/a n/a
Sources
cisa.gov CVE-2016-0752
euvd EUVD-2017-0333

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

References