{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "arbitrary file existence disclosure",
    "tracking": {
      "current_release_date": "2026-08-11T14:02:12+00:00",
      "generator": {
        "date": "2026-08-11T14:02:12+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2014-7818",
      "initial_release_date": "2014-10-31T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T14:02:12+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat CloudForms unspecified",
            "product": {
              "name": "Red Hat CloudForms unspecified",
              "product_id": "cfme-5",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:cloudforms_managementengine:5"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat OpenStack Platform",
            "product": {
              "name": "Red Hat OpenStack Platform",
              "product_id": "openstack-4",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:openstack:4"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Software Collections",
            "product": {
              "name": "Red Hat Software Collections",
              "product_id": "rhscl-1.2.z",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhel_software_collections:1"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Subscription Asset Manager 1.4",
            "product": {
              "name": "Red Hat Subscription Asset Manager 1.4",
              "product_id": "sam-1",
              "product_identification_helper": {
                "cpe": "cpe:/a:rhel_sam:1"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ror40-rubygem-actionpack",
            "product": {
              "name": "ror40-rubygem-actionpack",
              "product_id": "ror40-rubygem-actionpack",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ror40-rubygem-actionpack"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ror40-rubygem-actionpack-doc",
            "product": {
              "name": "ror40-rubygem-actionpack-doc",
              "product_id": "ror40-rubygem-actionpack-doc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ror40-rubygem-actionpack-doc"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ror40-rubygem-actionpack",
            "product": {
              "name": "ror40-rubygem-actionpack",
              "product_id": "ror40-rubygem-actionpack.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ror40-rubygem-actionpack?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ruby193-rubygem-actionpack",
            "product": {
              "name": "ruby193-rubygem-actionpack",
              "product_id": "ruby193-rubygem-actionpack",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ruby193-rubygem-actionpack"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ruby193-rubygem-actionpack-doc",
            "product": {
              "name": "ruby193-rubygem-actionpack-doc",
              "product_id": "ruby193-rubygem-actionpack-doc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ruby193-rubygem-actionpack-doc"
              }
            }
          },
          {
            "category": "product_version",
            "name": "ruby193-rubygem-actionpack",
            "product": {
              "name": "ruby193-rubygem-actionpack",
              "product_id": "ruby193-rubygem-actionpack.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/ruby193-rubygem-actionpack?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rubygem-actionpack",
            "product": {
              "name": "rubygem-actionpack",
              "product_id": "rubygem-actionpack",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rubygem-actionpack"
              }
            }
          },
          {
            "category": "product_version",
            "name": "rubygem-actionpack",
            "product": {
              "name": "rubygem-actionpack",
              "product_id": "rubygem-actionpack.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/rubygem-actionpack?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ror40-rubygem-actionpack as a component of Red Hat Software Collections",
          "product_id": "rhscl-1.2.z:ror40-rubygem-actionpack"
        },
        "product_reference": "ror40-rubygem-actionpack",
        "relates_to_product_reference": "rhscl-1.2.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ror40-rubygem-actionpack-doc as a component of Red Hat Software Collections",
          "product_id": "rhscl-1.2.z:ror40-rubygem-actionpack-doc"
        },
        "product_reference": "ror40-rubygem-actionpack-doc",
        "relates_to_product_reference": "rhscl-1.2.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ror40-rubygem-actionpack.src as a component of Red Hat Software Collections",
          "product_id": "rhscl-1.2.z:ror40-rubygem-actionpack.src"
        },
        "product_reference": "ror40-rubygem-actionpack.src",
        "relates_to_product_reference": "rhscl-1.2.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack as a component of Red Hat CloudForms unspecified",
          "product_id": "cfme-5:ruby193-rubygem-actionpack"
        },
        "product_reference": "ruby193-rubygem-actionpack",
        "relates_to_product_reference": "cfme-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack as a component of Red Hat OpenStack Platform",
          "product_id": "openstack-4:ruby193-rubygem-actionpack"
        },
        "product_reference": "ruby193-rubygem-actionpack",
        "relates_to_product_reference": "openstack-4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack as a component of Red Hat Subscription Asset Manager 1.4",
          "product_id": "sam-1:ruby193-rubygem-actionpack"
        },
        "product_reference": "ruby193-rubygem-actionpack",
        "relates_to_product_reference": "sam-1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack as a component of Red Hat Software Collections",
          "product_id": "rhscl-1.2.z:ruby193-rubygem-actionpack"
        },
        "product_reference": "ruby193-rubygem-actionpack",
        "relates_to_product_reference": "rhscl-1.2.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack-doc as a component of Red Hat Software Collections",
          "product_id": "rhscl-1.2.z:ruby193-rubygem-actionpack-doc"
        },
        "product_reference": "ruby193-rubygem-actionpack-doc",
        "relates_to_product_reference": "rhscl-1.2.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack-doc as a component of Red Hat OpenStack Platform",
          "product_id": "openstack-4:ruby193-rubygem-actionpack-doc"
        },
        "product_reference": "ruby193-rubygem-actionpack-doc",
        "relates_to_product_reference": "openstack-4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack.src as a component of Red Hat OpenStack Platform",
          "product_id": "openstack-4:ruby193-rubygem-actionpack.src"
        },
        "product_reference": "ruby193-rubygem-actionpack.src",
        "relates_to_product_reference": "openstack-4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack.src as a component of Red Hat CloudForms unspecified",
          "product_id": "cfme-5:ruby193-rubygem-actionpack.src"
        },
        "product_reference": "ruby193-rubygem-actionpack.src",
        "relates_to_product_reference": "cfme-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack.src as a component of Red Hat Software Collections",
          "product_id": "rhscl-1.2.z:ruby193-rubygem-actionpack.src"
        },
        "product_reference": "ruby193-rubygem-actionpack.src",
        "relates_to_product_reference": "rhscl-1.2.z"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "ruby193-rubygem-actionpack.src as a component of Red Hat Subscription Asset Manager 1.4",
          "product_id": "sam-1:ruby193-rubygem-actionpack.src"
        },
        "product_reference": "ruby193-rubygem-actionpack.src",
        "relates_to_product_reference": "sam-1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rubygem-actionpack as a component of Red Hat Subscription Asset Manager 1.4",
          "product_id": "sam-1:rubygem-actionpack"
        },
        "product_reference": "rubygem-actionpack",
        "relates_to_product_reference": "sam-1"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rubygem-actionpack.src as a component of Red Hat Subscription Asset Manager 1.4",
          "product_id": "sam-1:rubygem-actionpack.src"
        },
        "product_reference": "rubygem-actionpack.src",
        "relates_to_product_reference": "sam-1"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2014-7818",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "discovery_date": "2014-10-30T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "openstack-4:ruby193-rubygem-actionpack-doc",
            "rhscl-1.2.z:ror40-rubygem-actionpack-doc",
            "rhscl-1.2.z:ruby193-rubygem-actionpack-doc"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "Directory traversal vulnerability in actionpack/lib/action_dispatch/middleware/static.rb in Action Pack in Ruby on Rails 3.x before 3.2.20, 4.0.x before 4.0.11, 4.1.x before 4.1.7, and 4.2.x before 4.2.0.beta3, when serve_static_assets is enabled, allows remote attackers to determine the existence of files outside the application root via a /..%2F sequence.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "cfme-5:ruby193-rubygem-actionpack",
          "cfme-5:ruby193-rubygem-actionpack.src",
          "openstack-4:ruby193-rubygem-actionpack",
          "openstack-4:ruby193-rubygem-actionpack.src",
          "rhscl-1.2.z:ror40-rubygem-actionpack",
          "rhscl-1.2.z:ror40-rubygem-actionpack.src",
          "rhscl-1.2.z:ruby193-rubygem-actionpack",
          "rhscl-1.2.z:ruby193-rubygem-actionpack.src",
          "sam-1:ruby193-rubygem-actionpack",
          "sam-1:ruby193-rubygem-actionpack.src",
          "sam-1:rubygem-actionpack",
          "sam-1:rubygem-actionpack.src"
        ],
        "known_not_affected": [
          "openstack-4:ruby193-rubygem-actionpack-doc",
          "rhscl-1.2.z:ror40-rubygem-actionpack-doc",
          "rhscl-1.2.z:ruby193-rubygem-actionpack-doc"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2014-7818"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-7818"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2014-7818"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Will not fix",
          "product_ids": [
            "cfme-5:ruby193-rubygem-actionpack",
            "cfme-5:ruby193-rubygem-actionpack.src",
            "openstack-4:ruby193-rubygem-actionpack",
            "openstack-4:ruby193-rubygem-actionpack.src",
            "rhscl-1.2.z:ror40-rubygem-actionpack",
            "rhscl-1.2.z:ror40-rubygem-actionpack.src",
            "rhscl-1.2.z:ruby193-rubygem-actionpack",
            "rhscl-1.2.z:ruby193-rubygem-actionpack.src",
            "sam-1:ruby193-rubygem-actionpack",
            "sam-1:ruby193-rubygem-actionpack.src",
            "sam-1:rubygem-actionpack",
            "sam-1:rubygem-actionpack.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v2": {
            "version": "2.0",
            "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
            "baseScore": 5.0
          },
          "products": [
            "cfme-5:ruby193-rubygem-actionpack",
            "cfme-5:ruby193-rubygem-actionpack.src",
            "openstack-4:ruby193-rubygem-actionpack",
            "openstack-4:ruby193-rubygem-actionpack-doc",
            "openstack-4:ruby193-rubygem-actionpack.src",
            "rhscl-1.2.z:ror40-rubygem-actionpack",
            "rhscl-1.2.z:ror40-rubygem-actionpack-doc",
            "rhscl-1.2.z:ror40-rubygem-actionpack.src",
            "rhscl-1.2.z:ruby193-rubygem-actionpack",
            "rhscl-1.2.z:ruby193-rubygem-actionpack-doc",
            "rhscl-1.2.z:ruby193-rubygem-actionpack.src",
            "sam-1:ruby193-rubygem-actionpack",
            "sam-1:ruby193-rubygem-actionpack.src",
            "sam-1:rubygem-actionpack",
            "sam-1:rubygem-actionpack.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low",
          "product_ids": [
            "cfme-5:ruby193-rubygem-actionpack",
            "cfme-5:ruby193-rubygem-actionpack.src",
            "openstack-4:ruby193-rubygem-actionpack",
            "openstack-4:ruby193-rubygem-actionpack-doc",
            "openstack-4:ruby193-rubygem-actionpack.src",
            "rhscl-1.2.z:ror40-rubygem-actionpack",
            "rhscl-1.2.z:ror40-rubygem-actionpack-doc",
            "rhscl-1.2.z:ror40-rubygem-actionpack.src",
            "rhscl-1.2.z:ruby193-rubygem-actionpack",
            "rhscl-1.2.z:ruby193-rubygem-actionpack-doc",
            "rhscl-1.2.z:ruby193-rubygem-actionpack.src",
            "sam-1:ruby193-rubygem-actionpack",
            "sam-1:ruby193-rubygem-actionpack.src",
            "sam-1:rubygem-actionpack",
            "sam-1:rubygem-actionpack.src"
          ]
        }
      ],
      "title": "arbitrary file existence disclosure"
    }
  ]
}