VULNERABILITY INTELLIGENCE
CVE-2011-0449
CVSS score7.5 HIGH
EPSS probability2.50%
CISA KEVNot currently listed
Published2011-02-21
Last modified2026-06-16
Description
actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.