CVE-2019-11879
Dashboard / Vulnerabilities / CVE-2019-11879
CVE-2019-11879
Published: 10 May 2019Last Modified: 8 Jul 2026
Summary:
Details: The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore it is "not a problem.
References: https://bugs.ruby-lang.org/issues/15835
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 346c656620bd33bf090ca10785b7fa2b54ec2d55
Fixed -None
Affected versions
1.4.2
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
