{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-28T19:58:10.511","vulnerabilities":[{"cve":{"id":"CVE-2008-1145","sourceIdentifier":"secalert@redhat.com","published":"2008-03-04T23:44:00.000","lastModified":"2026-06-16T22:51:05.080","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) \"..%5c\" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option."},{"lang":"es","value":"Una vulnerabilidad de salto de directorio en WEBrick en Ruby versiones 1.8 anteriores a 1.8.5-p115 y 1.8.6-p114, y versiones 1.9 hasta 1.9.0-1, cuando se ejecuta en sistemas que admiten separadores de ruta de barra invertida (\\) o nombres de archivo sin distinción entre mayúsculas y minúsculas, permite a atacantes remotos acceder a archivos arbitrarios por medio  de secuencias o (1) \"..%5c\" (barra invertida codificada) o (2) nombres de archivo que coinciden con los patrones de la opción :NondisclosureName."}],"affected":[{"source":"secalert@redhat.com","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-22"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ruby-lang:webrick:-:*:*:*:*:ruby:*:*","matchCriteriaId":"8D531565-E826-4586-8A8A-B2C0206498D4"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*","versionStartIncluding":"1.8.0","versionEndExcluding":"1.8.5.115","matchCriteriaId":"3F33562B-11B4-4362-81EB-6A5181CA236C"},{"vulnerable":false,"criteria":"cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*","versionStartIncluding":"1.8.6","versionEndExcluding":"1.8.6.114","matchCriteriaId":"6D2EA115-6DE0-4633-A1AE-3069AC947973"},{"vulnerable":false,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0:*:*:*:*:*:*:*","matchCriteriaId":"52179EC7-CAF0-42AA-A21A-7105E10CA122"},{"vulnerable":false,"criteria":"cpe:2.3:a:ruby-lang:ruby:1.9.0.1:*:*:*:*:*:*:*","matchCriteriaId":"75AFC571-21D8-40F5-A0CF-20D3EC4E5FC3"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:7:*:*:*:*:*:*:*","matchCriteriaId":"E3EFD171-01F7-450B-B6F3-0F7E443A2337"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:8:*:*:*:*:*:*:*","matchCriteriaId":"72E4DB7F-07C3-46BB-AAA2-05CD0312C57F"}]}]}],"references":[{"url":"http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html","source":"secalert@redhat.com","tags":["Broken Link","Mailing List"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html","source":"secalert@redhat.com","tags":["Mailing List","Third Party Advisory"]},{"url":"http://secunia.com/advisories/29232","source":"secalert@redhat.com","tags":["Not Applicable","Vendor Advisory"]},{"url":"http://secunia.com/advisories/29357","source":"secalert@redhat.com","tags":["Not Applicable","Vendor Advisory"]},{"url":"http://secunia.com/advisories/29536","source":"secalert@redhat.com","tags":["Not Applicable"]},{"url":"http://secunia.com/advisories/30802","source":"secalert@redhat.com","tags":["Not Applicable"]},{"url":"http://secunia.com/advisories/31687","source":"secalert@redhat.com","tags":["Not Applicable"]},{"url":"http://secunia.com/advisories/32371","source":"secalert@redhat.com","tags":["Not Applicable"]},{"url":"http://support.apple.com/kb/HT2163","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"http://wiki.rpath.com/Advisories:rPSA-2008-0123","source":"secalert@redhat.com","tags":["Broken Link"]},{"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0123","source":"secalert@redhat.com","tags":["Broken Link"]},{"url":"http://www.kb.cert.org/vuls/id/404515","source":"secalert@redhat.com","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:141","source":"secalert@redhat.com","tags":["Broken Link"]},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:142","source":"secalert@redhat.com","tags":["Broken Link"]},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0897.html","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"http://www.ruby-lang.org/en/news/2008/03/03/webrick-file-access-vulnerability/","source":"secalert@redhat.com","tags":["Exploit","Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/archive/1/489205/100/0/threaded","source":"secalert@redhat.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/archive/1/489218/100/0/threaded","source":"secalert@redhat.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/archive/1/490056/100/0/threaded","source":"secalert@redhat.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/bid/28123","source":"secalert@redhat.com","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id?1019562","source":"secalert@redhat.com","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"http://www.vupen.com/english/advisories/2008/0787","source":"secalert@redhat.com","tags":["Permissions Required"]},{"url":"http://www.vupen.com/english/advisories/2008/1981/references","source":"secalert@redhat.com","tags":["Permissions Required"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41010","source":"secalert@redhat.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://issues.rpath.com/browse/RPL-2338","source":"secalert@redhat.com","tags":["Broken Link"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10937","source":"secalert@redhat.com","tags":["Broken Link"]},{"url":"https://www.exploit-db.com/exploits/5215","source":"secalert@redhat.com","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00338.html","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00354.html","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Mailing List"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"]},{"url":"http://secunia.com/advisories/29232","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable","Vendor Advisory"]},{"url":"http://secunia.com/advisories/29357","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable","Vendor Advisory"]},{"url":"http://secunia.com/advisories/29536","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]},{"url":"http://secunia.com/advisories/30802","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]},{"url":"http://secunia.com/advisories/31687","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]},{"url":"http://secunia.com/advisories/32371","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"]},{"url":"http://support.apple.com/kb/HT2163","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"http://wiki.rpath.com/Advisories:rPSA-2008-0123","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0123","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"http://www.kb.cert.org/vuls/id/404515","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"]},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:141","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:142","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0897.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"http://www.ruby-lang.org/en/news/2008/03/03/webrick-file-access-vulnerability/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/archive/1/489205/100/0/threaded","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/archive/1/489218/100/0/threaded","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/archive/1/490056/100/0/threaded","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/bid/28123","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id?1019562","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"]},{"url":"http://www.vupen.com/english/advisories/2008/0787","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"http://www.vupen.com/english/advisories/2008/1981/references","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/41010","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://issues.rpath.com/browse/RPL-2338","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10937","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://www.exploit-db.com/exploits/5215","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00338.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00354.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}],"vendorComments":[{"organization":"Red Hat","comment":"This issue was addressed in affected versions of Ruby as shipped in Red Hat Enterprise Linux 4 and 5 via: https://rhn.redhat.com/errata/RHSA-2008-0897.html","lastModified":"2008-12-04T00:00:00"}]}}]}