Bugzilla – Bug 1172037
VUL-0: CVE-2020-8161: rubygem-rack: directory traversal in Rack:Directory
Last modified: 2022-09-23 13:24:13 UTC
rh#1838281 There was a possible directory traversal vulnerability in the Rack::Directory app that is bundled with Rack. If certain directories exist in a director that is managed by `Rack::Directory`, an attacker could, using this vulnerability, read the contents of files on the server that were outside of the root specified in the Rack::Directory initializer. Reference: https://groups.google.com/forum/#!msg/rubyonrails-security/IOO1vNZTzPA/Ylzi1UYLAAAJ References: https://bugzilla.redhat.com/show_bug.cgi?id=1838281 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8161 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8161.html
SUSE-SU-2020:2678-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1159548,1172037,1173351 CVE References: CVE-2019-16782,CVE-2020-8161,CVE-2020-8184 JIRA References: Sources used: SUSE OpenStack Cloud Crowbar 9 (src): rubygem-rack-1.6.13-3.8.1 SUSE OpenStack Cloud Crowbar 8 (src): rubygem-rack-1.6.13-3.8.1 SUSE OpenStack Cloud 7 (src): rubygem-rack-1.6.13-3.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
https://bugzilla.redhat.com/show_bug.cgi?id=1838281#c9
15/rubygem-rack submitted.
SUSE-SU-2022:3347-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1172037,1173351 CVE References: CVE-2020-8161,CVE-2020-8184 JIRA References: Sources used: openSUSE Leap 15.4 (src): rubygem-rack-2.0.8-150000.3.9.1 openSUSE Leap 15.3 (src): rubygem-rack-2.0.8-150000.3.9.1 SUSE Linux Enterprise High Availability 15-SP4 (src): rubygem-rack-2.0.8-150000.3.9.1 SUSE Linux Enterprise High Availability 15-SP3 (src): rubygem-rack-2.0.8-150000.3.9.1 SUSE Linux Enterprise High Availability 15-SP2 (src): rubygem-rack-2.0.8-150000.3.9.1 SUSE Linux Enterprise High Availability 15-SP1 (src): rubygem-rack-2.0.8-150000.3.9.1 SUSE Linux Enterprise High Availability 15 (src): rubygem-rack-2.0.8-150000.3.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.