Количество 9
Количество 9
CVE-2018-3760
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.
CVE-2018-3760
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.
CVE-2018-3760
There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.
CVE-2018-3760
There is an information leak vulnerability in Sprockets. Versions Affe ...
openSUSE-SU-2018:2124-1
Security update for rubygem-sprockets
openSUSE-SU-2018:1854-1
Security update for rubygem-sprockets
SUSE-SU-2018:1994-1
Security update for rubygem-sprockets
GHSA-pr3h-jjhj-573x
Sprockets path traversal leads to information leak
BDU:2019-00440
Уязвимость Ruby-библиотеки для обслуживания веб-ресурсов Sprockets, связанная с ошибками обработки запросов, позволяющая нарушителю получить несанкционированный доступ к информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2018-3760 There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. | CVSS3: 7.5 | 94% Критический | больше 7 лет назад | |
CVE-2018-3760 There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. | CVSS3: 7.5 | 94% Критический | больше 7 лет назад | |
CVE-2018-3760 There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. | CVSS3: 7.5 | 94% Критический | больше 7 лет назад | |
CVE-2018-3760 There is an information leak vulnerability in Sprockets. Versions Affe ... | CVSS3: 7.5 | 94% Критический | больше 7 лет назад | |
openSUSE-SU-2018:2124-1 Security update for rubygem-sprockets | 94% Критический | больше 7 лет назад | ||
openSUSE-SU-2018:1854-1 Security update for rubygem-sprockets | 94% Критический | больше 7 лет назад | ||
SUSE-SU-2018:1994-1 Security update for rubygem-sprockets | 94% Критический | больше 7 лет назад | ||
GHSA-pr3h-jjhj-573x Sprockets path traversal leads to information leak | CVSS3: 7.5 | 94% Критический | больше 7 лет назад | |
BDU:2019-00440 Уязвимость Ruby-библиотеки для обслуживания веб-ресурсов Sprockets, связанная с ошибками обработки запросов, позволяющая нарушителю получить несанкционированный доступ к информации | CVSS3: 7.5 | 94% Критический | больше 7 лет назад |
Уязвимостей на страницу