actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2011-02-21T17:00:00

Updated: 2011-04-21T09:00:00

Reserved: 2011-01-13T00:00:00


Link: CVE-2011-0449

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2011-02-21T18:00:01.363

Modified: 2019-08-08T15:41:32.003


Link: CVE-2011-0449

JSON object: View

cve-icon Redhat Information

No data.

CWE