TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Rails Directory Traversal Vulnerability – Amended (CVE-2014-0130)

5 pointsby nfmabout 11 years ago

1 comment

nfmabout 11 years ago
This is a follow up from <a href="https://groups.google.com/forum/#!topic/rubyonrails-security/NkKc7vTW70o" rel="nofollow">https:&#x2F;&#x2F;groups.google.com&#x2F;forum&#x2F;#!topic&#x2F;rubyonrails-security...</a> (HN discussion: <a href="https://news.ycombinator.com/item?id=7705415" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=7705415</a>).<p>Additional attack vectors have been discovered, so you may be vulnerable even without &quot;*action&quot; globbing in your routes. All users are advised to upgrade to a fixed version or apply the supplied patches.