Candidate: CVE-2014-5269 PublicDate: 2014-09-04 17:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5269 https://github.com/plack/Plack/issues/405 Description: Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a crafted path, related to Plack::Middleware::Static. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_libplack-perl: upstream_libplack-perl: released (1.0031-1) lucid_libplack-perl: DNE precise_libplack-perl: ignored (reached end-of-life) precise/esm_libplack-perl: DNE (precise was needed) trusty_libplack-perl: ignored (reached end-of-life) trusty/esm_libplack-perl: DNE (trusty was needed) utopic_libplack-perl: not-affected (1.0031-1) vivid_libplack-perl: not-affected (1.0031-1) vivid/stable-phone-overlay_libplack-perl: DNE vivid/ubuntu-core_libplack-perl: DNE wily_libplack-perl: not-affected (1.0031-1) xenial_libplack-perl: not-affected (1.0031-1) yakkety_libplack-perl: not-affected (1.0031-1) zesty_libplack-perl: not-affected (1.0031-1) artful_libplack-perl: not-affected (1.0031-1) bionic_libplack-perl: not-affected (1.0031-1) cosmic_libplack-perl: not-affected (1.0031-1) disco_libplack-perl: not-affected (1.0031-1) devel_libplack-perl: not-affected (1.0031-1)