漏洞描述
Ruby On Rails is vulnerable to local file inclusion caused by secondary decoding in Sprockets 3.7.1 and lower versions. An attacker can use %252e%252e/ to access the root directory and read or execute any file on the target server.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/vulhub/vulhub/tree/master/rails/CVE-2018-3760↗i.blackhat.comhttps://i.blackhat.com/us-18/Wed-August-8/us-18-Orange-Tsai-Breaking-Parser-Logic-Take-Your-Path-Normalization-Off-And-Pop-0days-Out-2.pdf↗seclists.orghttps://seclists.org/oss-sec/2018/q2/210↗xz.aliyun.comhttps://xz.aliyun.com/t/2542↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2018-3760↗