CVE-2014-7819
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before…
Does this matter?
Lower severity and a low EPSS score (3.89%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.89% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- sprockets project/sprockets
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.htmlMailing List, Third Party Advisory
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJThird Party Advisory
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.htmlMailing List, Third Party Advisory
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJThird Party Advisory
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.