actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2011-02-21T17:00:00
Updated: 2011-04-21T09:00:00
Reserved: 2011-01-13T00:00:00
Link: CVE-2011-0449
JSON object: View
NVD Information
Status : Analyzed
Published: 2011-02-21T18:00:01.363
Modified: 2019-08-08T15:41:32.003
Link: CVE-2011-0449
JSON object: View
Redhat Information
No data.
CWE