Логотип exploitDog
bind:CVE-2018-3760
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-3760

Количество 9

Количество 9

ubuntu логотип

CVE-2018-3760

больше 7 лет назад

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2018-3760

больше 7 лет назад

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2018-3760

больше 7 лет назад

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2018-3760

больше 7 лет назад

There is an information leak vulnerability in Sprockets. Versions Affe ...

CVSS3: 7.5
EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2018:2124-1

больше 7 лет назад

Security update for rubygem-sprockets

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2018:1854-1

больше 7 лет назад

Security update for rubygem-sprockets

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2018:1994-1

больше 7 лет назад

Security update for rubygem-sprockets

EPSS: Критический
github логотип

GHSA-pr3h-jjhj-573x

больше 7 лет назад

Sprockets path traversal leads to information leak

CVSS3: 7.5
EPSS: Критический
fstec логотип

BDU:2019-00440

больше 7 лет назад

Уязвимость Ruby-библиотеки для обслуживания веб-ресурсов Sprockets, связанная с ошибками обработки запросов, позволяющая нарушителю получить несанкционированный доступ к информации

CVSS3: 7.5
EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-3760

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

CVSS3: 7.5
94%
Критический
больше 7 лет назад
redhat логотип
CVE-2018-3760

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

CVSS3: 7.5
94%
Критический
больше 7 лет назад
nvd логотип
CVE-2018-3760

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

CVSS3: 7.5
94%
Критический
больше 7 лет назад
debian логотип
CVE-2018-3760

There is an information leak vulnerability in Sprockets. Versions Affe ...

CVSS3: 7.5
94%
Критический
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:2124-1

Security update for rubygem-sprockets

94%
Критический
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2018:1854-1

Security update for rubygem-sprockets

94%
Критический
больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2018:1994-1

Security update for rubygem-sprockets

94%
Критический
больше 7 лет назад
github логотип
GHSA-pr3h-jjhj-573x

Sprockets path traversal leads to information leak

CVSS3: 7.5
94%
Критический
больше 7 лет назад
fstec логотип
BDU:2019-00440

Уязвимость Ruby-библиотеки для обслуживания веб-ресурсов Sprockets, связанная с ошибками обработки запросов, позволяющая нарушителю получить несанкционированный доступ к информации

CVSS3: 7.5
94%
Критический
больше 7 лет назад

Уязвимостей на страницу