GHSA-xrr4-p6fq-hjg7 · Severity: high · Ecosystem: rubygems — Directory traversal vulnerability in Action View in Ruby on Rails
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
Conclusion & alert: CVE-2016-0752 is rated Critical Active Threat (89.3/100): CVSS High severity, with high exploitation likelihood (EPSS 90.49%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-03-25) affecting Rails / Ruby on Rails. a weakness (CWE-22) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Ruby on Rails Directory Traversal Vulnerability · CISA KEV detail
: 2022-03-25
: 2022-04-15
: Apply updates per vendor instructions.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 40561 | exploit_db | edb | 2016-10-17 | Exploit-DB ↗ |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-23 | 91.05% | 90.49% | -0.56% |
| 2 | 2026-03-18 | 92.60% | 91.05% | -1.55% |
| 3 | 2026-03-17 | — | 92.60% | — |
Full EPSS history (40 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
GHSA-xrr4-p6fq-hjg7 · Severity: high · Ecosystem: rubygems — Directory traversal vulnerability in Action View in Ruby on Rails
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2016-0752 not yet assigned priority: Debian including 1 source packages (rails), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2016-0752 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2016-0752 |
suse
|
medium | CVE-2016-0752 severity moderate: SUSE including 17 source package names (libcontainment-insomnia-0.1.1-0.9.4.19, libjansson4-2.2.1-0.9.11.6, …), 33 product×package rows across 9 product lines (SUSE Enterprise Storage 2.1, SUSE Lifecycle Management Server 1.3, … (9 product lines)): Fixed 33. | https://www.suse.com/security/cve/CVE-2016-0752/ |
ubuntu
|
medium | CVE-2016-0752 medium priority: Ubuntu including 10 source packages (rails, rails-4.0, …), 120 status rows across 12 suites (artful, bionic, cosmic, disco, precise, trusty, upstream, vivid, wily, xenial, yakkety, zesty): DNE 96, ignored 12, needs-triage 5, not-affected 5, released 2. | https://ubuntu.com/security/CVE-2016-0752 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| rubyonrails | rails | < 3.2.22.1 | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* |
| rubyonrails | rails | >= 4.0.0, < 4.1.14.1 | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* |
| rubyonrails | rails | >= 4.2.0, < 4.2.5.1 | cpe:2.3:a:rubyonrails:rails:*:*:*:*:*:*:*:* |
| rubyonrails | rails | 5.0.0 | cpe:2.3:a:rubyonrails:rails:5.0.0:beta1:*:*:*:*:*:* |
| opensuse | leap | 42.1 | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
| opensuse | opensuse | 13.2 | cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:* |
| suse | linux_enterprise_module_for_containers | 12 | cpe:2.3:o:suse:linux_enterprise_module_for_containers:12:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| redhat | software_collections | 1.0 | cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:* |