Description
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Intercom-Slack for WordPress Information Disclosure (1.2.1)
Magento Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2019-7950)
MySQL CVE-2019-2812 Vulnerability (CVE-2019-2812)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3472)
Chart.js Improper Input Validation Vulnerability (CVE-2020-7746)