Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.
| Software | From | Fixed in |
|---|---|---|
| schneems / wicked | - | 1.0.0.x |
| schneems / wicked | 0.0.1 | 0.0.1.x |
| schneems / wicked | 0.0.2 | 0.0.2.x |
| schneems / wicked | 0.1.0 | 0.1.0.x |
| schneems / wicked | 0.1.1 | 0.1.1.x |
| schneems / wicked | 0.1.2 | 0.1.2.x |
| schneems / wicked | 0.1.3 | 0.1.3.x |
| schneems / wicked | 0.1.4 | 0.1.4.x |
| schneems / wicked | 0.1.5 | 0.1.5.x |
| schneems / wicked | 0.1.6 | 0.1.6.x |
| schneems / wicked | 0.2.0 | 0.2.0.x |
| schneems / wicked | 0.3.0 | 0.3.0.x |
| schneems / wicked | 0.3.1 | 0.3.1.x |
| schneems / wicked | 0.3.2 | 0.3.2.x |
| schneems / wicked | 0.3.3 | 0.3.3.x |
| schneems / wicked | 0.3.4 | 0.3.4.x |
| schneems / wicked | 0.4.0 | 0.4.0.x |
| schneems / wicked | 0.5.0 | 0.5.0.x |
| schneems / wicked | 0.6.0 | 0.6.0.x |
| schneems / wicked | 0.6.1 | 0.6.1.x |
wicked
|
- | 1.0.1 |