Description
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
Remediation
References
Related Vulnerabilities
WordPress Plugin Knews Multilingual Newsletters SQL Injection (1.7.0)
MySQL CVE-2020-14632 Vulnerability (CVE-2020-14632)
Opencart Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2023-47444)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-7834)
Atlassian Jira Missing Authorization Vulnerability (CVE-2019-3399)