VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 17 hours ago

CVE-2016-0752

7.5 High Protected by RASP

Description

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

CWE-22 · Path traversal

Exploitation Status

Exploited in the wild

Confirmed real-world exploitation.

CVSS E:A

  • CISA KEV listed Confirmed exploitation in the wild. Added 2022-03-25 · remediation due 2022-04-15 · ransomware use: unknown
  • CISA Vulnrichment exploitation: active CISA records active exploitation. Automatable: yes, technical impact: partial.
  • Indexed PoC 2 indexed Published artifacts you can open, in Exploit-DB, GitHub PoC; first seen 2016-01-26.
  • EPSS 96% chance in 30 days A model prediction, not an observation. Higher than 100% of all scored CVEs.
IndexArtifactStarsFirst seen
GitHub PoC forced-request/rails-rce-cve-2016-0752 10 2016-01-26
Exploit-DB Ruby on Rails - Dynamic Render File Upload / Remote Code Execution (Metasploit) 2016-10-17

Waratek Defense Posture

Protected by RASP

A Waratek agent blocks this today.

Applicable rule: Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-22: Path Traversal) can be mitigated by an ARMR path-traversal security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.

  • Protection full a general security rule for the vulnerability class
  • Action available security rule
  • Review automated inferred
  • Record active
Decided by secure-rule-match : A vulnerability class already blocked by an ARMR security rule
Finding Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-22: Path Traversal) can be mitigated by an ARMR path-traversal security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.

CVSS

7.5 HIGH v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 3 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N NVD Primary published
CVSS 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CISA-ADP Secondary
CVSS 2.0 5.0 no band published AV:N/AC:L/Au:N/C:P/I:N/A:N NVD Primary

Affected Software & Releases

🖥️ Product CPEs & Version Ranges

6 product(s) over 9 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd debian debian linux generic 8.0
nvd opensuse leap generic 42.1
nvd opensuse opensuse generic 13.2
nvd redhat software collections generic 1.0
nvd rubyonrails rails generic < 3.2.22.1 · ≥ 4.0.0 and < 4.1.14.1 · ≥ 4.2.0 and < 4.2.5.1 · 5.0.0:beta1
nvd suse linux enterprise module for containers generic 12

References

URLTags
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178044.html Permissions Required
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/178069.html Permissions Required
http://lists.opensuse.org/opensuse-security-announce/2016-04/msg00053.html Mailing List, Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2016-02/msg00034.html Mailing List, Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2016-02/msg00043.html Mailing List, Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-0296.html Third Party Advisory
http://www.debian.org/security/2016/dsa-3464 Mailing List, Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/01/25/13 Exploit, Mailing List
http://www.securityfocus.com/bid/81801 Broken Link, Third Party Advisory, VDB Entry
http://www.securitytracker.com/id/1034816 Broken Link, Third Party Advisory, VDB Entry

Timeline

Published 2016-02-16 Last modified 2026-06-17
Published2016-02-16By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.