Unrated severityNVD Advisory· Published Sep 4, 2014· Updated May 6, 2026
CVE-2014-5269
CVE-2014-5269
Description
Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a crafted path, related to Plack::Middleware::Static.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- github.com/avar/Plack/commit/bc1731dbb53850c380875ad683cd87c8ec99eee3nvdPatchVendor Advisory
- github.com/plack/Plack/issues/405nvdPatchVendor Advisory
- api.metacpan.org/source/MIYAGAWA/Plack-1.0031/Changesnvd
- lists.fedoraproject.org/pipermail/package-announce/2014-August/137099.htmlnvd
- lists.fedoraproject.org/pipermail/package-announce/2014-August/137115.htmlnvd
- seclists.org/oss-sec/2014/q3/384nvd
- www.osvdb.org/109928nvd
News mentions
0No linked articles in our index yet.