Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 RubyGems

Arbitrary file read vulnerability in yard server

GHSA-gj4p-3wh3-2rmf · CVE-2017-17042

Published · Modified

Description

lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.

Ready to move

Start Securing

Free, no credit card | First findings in minutes