CVE-2012-2139

EPSS 3.5%

Mail Gem Path Traversal vulnerability

Published: 10/24/2017Modified: 4/28/2026

Description

Directory traversal vulnerability in lib/mail/network/delivery_methods/file_delivery.rb in the Mail gem before 2.4.4 for Ruby allows remote attackers to read arbitrary files via a .. (dot dot) in the to parameter.

Affected packages (2)

References (11)