actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2011-02-21T17:00:00

Updated: 2024-08-06T21:51:09.091Z

Reserved: 2011-01-13T00:00:00

Link: CVE-2011-0449

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2011-02-21T18:00:01.363

Modified: 2019-08-08T15:41:32.003

Link: CVE-2011-0449

cve-icon Redhat

No data.