Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
References
Link | Resource |
---|---|
http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.html | Mailing List Third Party Advisory |
http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.html | Mailing List Third Party Advisory |
https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJ | Third Party Advisory |
https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJ | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2014-11-08T11:00:00
Updated: 2014-12-01T15:57:00
Reserved: 2014-10-03T00:00:00
Link: CVE-2014-7819
JSON object: View
NVD Information
Status : Modified
Published: 2014-11-08T11:55:03.023
Modified: 2023-02-13T00:42:25.267
Link: CVE-2014-7819
JSON object: View
Redhat Information
No data.
CWE