Vulnerability record · CVE-2019-11879 · published 10 May 2019
CVE-2019-11879: Ruby-lang webrick path traversal vulnerability
Ruby Lang · Webrick
The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore it is "not a problem.
Description
The WEBrick gem 1.4.2 for Ruby allows directory traversal if the attacker once had local access to create a symlink to a location outside of the web root directory. NOTE: The vendor states that this is analogous to Options FollowSymlinks in the Apache HTTP Server, and therefore it is "not a problem.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugs.ruby-lang.org/issues/15835 | Issue TrackingVendor Advisory |
| https://bugs.ruby-lang.org/issues/15835 | Issue TrackingVendor Advisory |
Track CVE-2019-11879 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11879), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.