Loading
Generated remediation guidance and an executive summary. No account required.
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.
Use CWE-22, Rubyonrails vendor hub and Rails product page to widen CVE-2016-0752 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-33195, CVE-2024-26142 and CVE-2026-33169 for nearby disclosures in the same product family.