← Back

CVE-2013-4413

nvd nist
Published: Mar 11, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.

Affected (20)

Products: Schneems: Wicked
1 product
Wicked
Configuration A
20 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Schneems
Up to 1.0.0
Version 0.0.1
Version 0.0.2
Version 0.1.0
Version 0.1.1
Version 0.1.2
Version 0.1.3
Version 0.1.4
Version 0.1.5
Version 0.1.6
Version 0.2.0
Version 0.3.0
Version 0.3.1
Version 0.3.2
Version 0.3.3
Version 0.3.4
Version 0.4.0
Version 0.5.0
Version 0.6.0
Version 0.6.1
Running on/withPlatform Versions
Ruby Lang
Ruby
All versions

References (10)

Source: secalert@redhat.com
Patch
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatch

Timeline

No history available yet.