Oval Definition:oval:org.opensuse.security:def:20147818
Revision Date:2022-06-30Version:1
Title:CVE-2014-7818
Description:

Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2014-7818
Mitre CVE-2014-7818
SUSE CVE-2014-7818
openSUSE-SU-2014:1515-1
openSUSE-SU-2014:1515-1
SUSE-SU-2015:0156-1
SUSE-SU-2015:0156-1
SUSE-SU-2015:0863-1
SUSE-SU-2015:0863-1
Platform(s):openSUSE 12.3 Update
openSUSE 13.1
openSUSE 13.2
openSUSE Tumbleweed
SUSE Linux Enterprise High Availability 15
SUSE Linux Enterprise High Availability 15 SP1
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Software Development Kit 11 SP4
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Retail Branch Server 4.0
SUSE Manager Server 4.0
SUSE OpenStack Cloud 6
SUSE OpenStack Cloud 7
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE 13.1 is installed
  • AND Package Information
  • rubygem-actionpack-3_2-3.2.13-2.28.1 is installed
  • OR rubygem-actionpack-3_2-doc-3.2.13-2.28.1 is installed
  • Definition Synopsis
  • openSUSE 13.2 is installed
  • AND Package Information
  • rubygem-actionpack-3_2-3.2.17-3.4.1 is installed
  • OR rubygem-actionpack-3_2-doc-3.2.17-3.4.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Software Development Kit 11 SP4 is installed
  • AND rubygem-actionpack-3_2-3.2.12-0.19 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 6 is installed
  • AND ruby2.1-rubygem-actionpack-4_2-4.2.2-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND ruby2.5-rubygem-actionpack-5_1-5.1.4-1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND ruby2.5-rubygem-actionpack-5_1-5.1.4-1 is installed
  • OR Package Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND ruby2.5-rubygem-actionpack-5_1-5.1.4-3.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 7 is installed
  • AND Package Information
  • rubygem-actionmailer-4_2 is affected
  • OR rubygem-actionpack-4_2 is affected
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND ruby2.5-rubygem-actionpack-5_1-5.1.4-3.3 is installed
  • Definition Synopsis
  • openSUSE Tumbleweed is installed
  • AND Package Information
  • ruby2.2-rubygem-actionpack-4_2-4.2.7.1-1.1 is installed
  • OR ruby2.2-rubygem-actionpack-5_0-5.0.0.1-1.1 is installed
  • OR ruby2.2-rubygem-actionpack-doc-4_2-4.2.7.1-1.1 is installed
  • OR ruby2.2-rubygem-actionpack-doc-5_0-5.0.0.1-1.1 is installed
  • OR ruby2.3-rubygem-actionpack-4_2-4.2.7.1-1.1 is installed
  • OR ruby2.3-rubygem-actionpack-5_0-5.0.0.1-1.1 is installed
  • OR ruby2.3-rubygem-actionpack-doc-4_2-4.2.7.1-1.1 is installed
  • OR ruby2.3-rubygem-actionpack-doc-5_0-5.0.0.1-1.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND ruby2.5-rubygem-actionpack-5_1-5.1.4-3.3.1 is installed
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 is installed
  • AND ruby2.5-rubygem-actionpack-5_1-5.1.4-1.26 is installed
  • OR Package Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • AND ruby2.5-rubygem-actionpack-5_1-5.1.4-3.3.1 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • ruby2.1-rubygem-actionmailer-4_2 is affected
  • OR ruby2.1-rubygem-actionpack-4_2 is affected
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • ruby2.1-rubygem-actionmailer-4_2 is affected
  • OR ruby2.1-rubygem-actionpack-4_2 is affected
  • Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Availability 15 SP1 is installed
  • OR SUSE Linux Enterprise High Performance Computing 15 SP1 is installed
  • OR SUSE Linux Enterprise Server 15 SP1 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP1 is installed
  • OR SUSE Manager Proxy 4.0 is installed
  • OR SUSE Manager Retail Branch Server 4.0 is installed
  • OR SUSE Manager Server 4.0 is installed
  • AND ruby2.5-rubygem-actionpack-5_1-5.1.4-3.3.1 is installed
  • BACK