CVE-2014-0130 is a directory traversal vulnerability in Action Pack's implicit-render implementation in Ruby on Rails prior to 3.2.18, 4.0.5, and 4.1.1. Under certain route-globbing configurations, attacker-controlled route data can be interpreted during implicit template resolution. A crafted request containing traversal sequences can cause Rails to resolve and render files outside the intended view directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a Ruby on Rails 3.2.1 application designed as a test case for CVE-2014-0130, a directory traversal vulnerability in Rails route globbing. The structure is that of a standard Rails app, with controllers, views, assets, and configuration files. The key exploit capability is demonstrated in the README, which provides a payload that targets the '/api/*action' route, exploiting improper sanitization of backslash-encoded directory traversal sequences. This allows an attacker to access arbitrary files on the server by sending crafted HTTP requests. The application is not a detection script but a proof-of-concept vulnerable app for demonstrating the exploit. The main fingerprintable endpoint is the '/api/*action' route, and the payload is a specially crafted HTTP GET request. The repository references public advisories and reports for further context. No weaponized or framework-based code is present; this is a standalone POC for research and demonstration purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Ruby on Rails wildcard-routing and implicit-template-rendering path-traversal vulnerability. In the described vulnerable configuration, attacker-controlled action paths can cause unintended template or file resolution, enabling file disclosure and potentially remote code execution when an attacker also has an ability to write a malicious ERB template or controller file.
A directory traversal vulnerability in web servers due to improper URI/input sanitization, enabling unauthenticated attackers to access arbitrary files.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.