HIGH 7.5 RubyGems

Arbitrary file read vulnerability in yard server

GHSA-gj4p-3wh3-2rmf · CVE-2017-17042

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.

Ready to move

Start Securing

Free, no credit card | First findings in minutes