Mongrel vulnerable to directory traversal via double-encoded sequences
Moderate severity
GitHub Reviewed
Published
May 1, 2022
to the GitHub Advisory Database
•
Updated Sep 21, 2023
Description
Published by the National Vulnerability Database
Jan 3, 2008
Published to the GitHub Advisory Database
May 1, 2022
Reviewed
Sep 21, 2023
Last updated
Sep 21, 2023
Directory traversal vulnerability in DirHandler (lib/mongrel/handlers.rb) in Mongrel 1.0.4 (1.0.3 and prior are not affected) and 1.1.x before 1.1.3 allows remote attackers to read arbitrary files via an HTTP request containing double-encoded sequences (
.%252e
).References