Yardoc
Yardoc Yard: vulnerabilidades y CVE
Yardoc Yard tiene 5 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses2
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-49342 | Media (5.3) | 0.40% | — | 19 jun 2026 | YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with… |
| CVE-2026-41493 | Media (6.9) | 0.52% | — | 8 may 2026 | YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access… |
| CVE-2024-27285 | Media (6.1) | 1.1% | — | 28 feb 2024 | YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the… |
| CVE-2019-1020001 | Alta (7.5) | 2.3% | — | 29 jul 2019 | yard before 0.9.20 allows path traversal. |
| CVE-2017-17042 | Alta (7.5) | 2.9% | — | 28 nov 2017 | lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files. |