Rails version with file disclosure vulnerability detected RB-A1003

cwe-200 sans top 25 owasp top 10

Selected versions of Rails 2, 3 & 4 are vulnerable to file disclosures. Upgrading to newer versions of Rails or disabling serving of static assets, if enabled, can help fix this issue.

In vulnerable Rails versions, when serve_static_assets is enabled, remote attackers can determine the existence of files outside the application root via vectors involving a backslash character.


