CVE-2014-0130Patch(redhat / enterprise_linux_server)

LOWCVSS 7.5 · HIGHCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch redhat enterprise_linux_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 3.2.18, 4.0.x before 4.0.5, and 4.1.x before 4.1.1, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request.

1.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-04-15. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • enterprise_linux_server
  • rails
  • subscription_asset_manager

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
enterprise_linux_serverrailssubscription_asset_manager

1 version affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-30: 1Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-30: 104-30
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH SEVERITY: CVE-2014-0130 (CVSS 7.5) Directory traversal flaw in Ruby on Rails <3.2.18, 4.0.x <4.0.5, 4.1.x <4.1.1 allows remote attackers to read arbitrary files via crafted requests. Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/PgUEP1vxRY

    Post summary

    The tweet highlights a high‑severity directory traversal vulnerability in Ruby on Rails and stresses the urgency of applying the available patch.

    0000029
    11 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSredhatenterprise_linux_server6.0--
Appredhatsubscription_asset_manager---
Apprubyonrailsrails---

Explore more