Path traversal in Rack - CVE-2020-8161

 

Path traversal in Rack - CVE-2020-8161

Published: September 23, 2022


Vulnerability identifier: #VU67622
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8161
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in Rack::Directory app. A remote attacker can send a specially crafted request and read arbitrary files on the system.


Affected software

Rack
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Storage
Fedora
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise High Availability
SUSE Linux Enterprise Server
openSUSE Leap
Ubuntu
ruby-rack (Ubuntu package)
ruby2.5-rubygem-rack
ruby2.5-rubygem-rack-doc
ruby2.5-rubygem-rack-testsuite
rubygem-rack
IBM Watson Discovery for IBM Cloud Pak for Data

How to mitigate CVE-2020-8161

Install update from vendor's website.

Rack - update to 2.1.3
ruby-rack (Ubuntu package) - addressed in versions 1.6.4-3ubuntu0.2, 1.6.4-4ubuntu0.2, 2.0.7-2ubuntu0.1, 2.1.1-5ubuntu0.1
ruby2.5-rubygem-rack - update to 2.0.8-150000.3.9.1
ruby2.5-rubygem-rack-doc - update to 2.0.8-150000.3.9.1
ruby2.5-rubygem-rack-testsuite - update to 2.0.8-150000.3.9.1
rubygem-rack - update to 2.2.2-1.el8
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.8, 5.1.0

External References

Related Security Bulletins