CVE-2014-0130 Details
Description
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
A directory traversal vulnerability has been identified in Ruby on Rails versions prior to 3.2.18, 4.0.x prior to 4.0.5, and 4.1.x prior to 4.1.1. The vulnerability exists in the implicit-render implementation of Action Pack, specifically within the abstract controller base. When certain route globbing configurations are enabled, remote attackers can read arbitrary files by sending a crafted request that exploits this directory traversal flaw.
Users are advised to upgrade to Ruby on Rails versions 3.2.18, 4.0.5, or 4.1.1. For Red Hat Subscription Asset Manager users, this update is available through the Red Hat Network.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0130 | CISA-ADP | US Government Resource |
| http://matasano.com/research/AnatomyOfRailsVuln-CVE-2014-0130.pdf | CVE | Broken LinkTechnical Description |
| http://rhn.redhat.com/errata/RHSA-2014-1863.html | CVE | Third Party Advisory |
| https://groups.google.com/forum/message/raw?msg=rubyonrails-security/NkKc7vTW70o/NxW_PDBSG3AJ | CVE | Broken LinkThird Party Advisory |
| http://www.securityfocus.com/bid/67244 | CVE | Broken LinkThird Party AdvisoryVDB Entry |
| http://matasano.com/research/AnatomyOfRailsVuln-CVE-2014-0130.pdf | [email protected] | Broken LinkTechnical Description |
| http://rhn.redhat.com/errata/RHSA-2014-1863.html | [email protected] | Third Party Advisory |
| https://groups.google.com/forum/message/raw?msg=rubyonrails-security/NkKc7vTW70o/NxW_PDBSG3AJ | [email protected] | Broken LinkThird Party Advisory |
| http://www.securityfocus.com/bid/67244 | [email protected] | Broken LinkThird Party AdvisoryVDB Entry |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Ruby on Rails Directory Traversal Vulnerability | Mar 25, 2022 | Apr 15, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| redhat subscription asset manager | <= 1.3.0 |
CPE
Remediation
| |
| redhat enterprise linux server | 6.0 |
CPE
Remediation
| |
| rubyonrails rails | < 3.2.18 >= 4.0.0, < 4.0.5 >= 4.1.0, < 4.1.1 |
CPE
Remediation
| |
Change History
55 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Apr 3, 2025 | Modified Analysis | [email protected] |
| Feb 7, 2025 | CVE Modified | CISA-ADP |
| Dec 19, 2024 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 16, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 13, 2023 | CVE Modified | [email protected] |
| Feb 2, 2023 | CVE Modified | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Aug 8, 2019 | CPE Deprecation Remap | [email protected] |
| Nov 17, 2016 | Modified Analysis | [email protected] |
| Jun 4, 2015 | CVE Modified | [email protected] |
| Dec 12, 2014 | CVE Modified | [email protected] |
| May 7, 2014 | Initial Analysis | [email protected] |