Skip to content

Path Traversal vulnerability that affects yard

High severity GitHub Reviewed Published Jun 28, 2019 in lsegal/yard • Updated Mar 7, 2024

Package

bundler yard (RubyGems)

Affected versions

< 0.9.20

Patched versions

0.9.20

Description

Possible arbitrary path traversal and file access via yard server

Impact

A path traversal vulnerability was discovered in YARD <= 0.9.19 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions.

Thanks to CuongMX from Viettel Cyber Security for discovering this vulnerability.

Patches

Please upgrade to YARD v0.9.20 immediately if you are relying on yard server to host documentation in any untrusted environments.

Workarounds

For users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration.

References

@lsegal lsegal published to lsegal/yard Jun 28, 2019
Published to the GitHub Advisory Database Jul 2, 2019
Published by the National Vulnerability Database Jul 29, 2019
Reviewed Jun 16, 2020
Last updated Mar 7, 2024

Severity

High
7.5
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CVE ID

CVE-2019-1020001

GHSA ID

GHSA-xfhh-rx56-rxcr

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.