CVE-2014-0130: Ruby on Rails Directory Traversal Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2022-03-25. EPSS: 53.7% chance of exploitation in the next 30 days.
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.
Affected products
- Red Hat Enterprise Linux Server: version 6.0 only
- Red Hat Subscription Asset Manager: up to and including 1.3.0
- Rubyonrails Rails: before 3.2.18 (fixed in 3.2.18); from 4.0.0, before 4.0.5 (fixed in 4.0.5); from 4.1.0, before 4.1.1 (fixed in 4.1.1)
Published 2014-05-07. Last modified 2026-06-17.