message_bus
A reliable and robust messaging bus for Ruby and Rack
Activity
- Latest release
- 1w ago
- Total releases
- 94
- Cadence
- ~25 days
- Last 12 months
- 5
Reach
- Downloads
- 2.8M
- Stars
- 1.7k
Details
- License
- MIT
- First release
- May 15, 2013
| Version | Released | |
|---|---|---|
5.0.0
major
|
5.0.0
major
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
4.6.0
minor
|
4.6.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
4.5.2
patch
|
4.5.2
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.5.1
patch
|
4.5.1
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.5.0
minor
|
4.5.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.4.1
patch
|
4.4.1
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
4.4.0
minor
|
4.4.0
minor
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
4.3.9
patch
|
4.3.9
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
4.3.8
patch
|
4.3.8
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.3.7
patch
|
4.3.7
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.3.6
patch
|
4.3.6
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.3.4
patch
|
4.3.4
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.3.3
patch
|
4.3.3
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.3.2
patch
|
4.3.2
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.3.1
patch
|
4.3.1
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.3.0
minor
|
4.3.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.2.0
minor
|
4.2.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.1.0
minor
|
4.1.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.0.0
major
|
4.0.0
major
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.4.0
minor
|
3.4.0
minor
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.3.8
patch
|
3.3.8
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.3.7
patch
|
3.3.7
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.3.6
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.5
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.4
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.3
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.2
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.1
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.3.0
minor
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.2.0
minor
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.1.0
minor
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
3.0.0
major
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.4
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.3
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.2
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.1
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.0
minor
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.0.pre.2
pre
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.0.pre.1
pre
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.2.0.pre
pre
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.6
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.5
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.3
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.4
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.2
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.1
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.1.0
minor
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.9
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.8
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
2.0.7
patch
1 CVE
CVE-2021-43840
GHSA-xmgj-5fh3-xjmm
Dec 17, 2021
Path traversal when MessageBus::Diagnostics is enabled
4.2
/ 10
Medium
Network
High
High
Required
Unchanged
High
None
None
ImpactUsers who deployed message bus with diagnostics features enabled (default off) were vulnerable to a path traversal bug, which could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. The impact is also greater if there is no proxy for your web application as the number of steps up the directories is not bounded. For deployments which uses a proxy, the impact varies. For example, If a request goes through a proxy like Nginx with PatchesPatched in 3.3.7. WorkaroundsDisable MessageBus::Diagnostics in production like environments. Affected versions
0.0.1
0.0.2
0.9.3
0.9.3.1
0.9.3.2
0.9.4
0.9.5
0.9.6
1.0.0
1.0.1
1.0.10
1.0.11
+ 60 more Show less
1.0.12
1.0.13
1.0.14
1.0.15
1.0.16
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.1.1
2.0.0
2.0.0.beta.1
2.0.0.beta.10
2.0.0.beta.11
2.0.0.beta.2
2.0.0.beta.3
2.0.0.beta.4
2.0.0.beta.5
2.0.0.beta.6
2.0.0.beta.7
2.0.0.beta.8
2.0.0.beta.9
2.0.1
2.0.2
2.0.3
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.0.pre
2.2.0.pre.1
2.2.0.pre.2
2.2.1
2.2.2
2.2.3
2.2.4
3.0.0
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
Fixed in
3.3.7
References
Updated Jul 08, 2026 · Source: OSV.dev |