Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Pagy I18n locale option is not validated before being used in a file path
Vulnerability Description
Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values verbatim and later used them as <locale>.yml path components, allowing untrusted params[:locale] values with absolute paths or ../ sequences to create a file existence and readability oracle for YAML files. This issue is fixed in version 43.5.6.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Domizio Demichelis Pagy 信息泄露漏洞
Vulnerability Description
Domizio Demichelis Pagy是Domizio Demichelis个人开发者的一款分页组件。 Domizio Demichelis Pagy 43.0.0版本至43.5.6之前版本存在安全漏洞,该漏洞源于Pagy::I18n.locale=方法将locale值原样存储并用作<locale>.yml路径组件,允许不受信任的params[:locale]值包含绝对路径或../序列,进而导致路径遍历和信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A