Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-3760

Опубликовано: 26 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS2: 5
CVSS3: 7.5

Описание

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

РелизСтатусПримечание
artful

released

3.7.0-1+deb9u1build0.17.10.1
bionic

released

3.7.0-1+deb9u1build0.18.04.1
cosmic

ignored

end of life
devel

not-affected

3.7.2-1
disco

not-affected

3.7.2-1
eoan

not-affected

3.7.2-1
esm-apps/bionic

released

3.7.0-1+deb9u1build0.18.04.1
esm-apps/focal

not-affected

3.7.2-1
esm-apps/jammy

not-affected

3.7.2-1
esm-apps/noble

not-affected

3.7.2-1

Показывать по

EPSS

Процентиль: 100%
0.93887
Критический

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

CVSS3: 7.5
nvd
больше 7 лет назад

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

CVSS3: 7.5
debian
больше 7 лет назад

There is an information leak vulnerability in Sprockets. Versions Affe ...

suse-cvrf
больше 7 лет назад

Security update for rubygem-sprockets

suse-cvrf
больше 7 лет назад

Security update for rubygem-sprockets

EPSS

Процентиль: 100%
0.93887
Критический

5 Medium

CVSS2

7.5 High

CVSS3