Selected versions of Rails 2, 3 & 4 are vulnerable to file disclosures. Upgrading to newer versions of Rails or disabling serving of static assets, if enabled, can help fix this issue.
In vulnerable Rails versions, when serve_static_assets
is enabled, remote attackers can determine the existence of files outside the application root via vectors involving a backslash character.