CVE-2014-7819: Path Traversal
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-7819?
CVE-2014-7819 has been classified as a moderate severity vulnerability impacting multiple versions of the Sprockets component.
How do I fix CVE-2014-7819?
To mitigate CVE-2014-7819, upgrade Sprockets to versions 2.0.5, 2.1.4, 2.2.3, 2.3.3, 2.4.6, 2.5.1, 2.7.1, 2.8.3, 2.9.4, 2.10.2, 2.11.3 or later.
What are the impacts of CVE-2014-7819?
Exploitation of CVE-2014-7819 could allow attackers to traverse directories and access sensitive files on the server.
Which versions of Sprockets are affected by CVE-2014-7819?
CVE-2014-7819 affects Sprockets versions prior to 2.0.5, 2.1.4, 2.2.3, 2.3.3, 2.4.6, 2.5.1, 2.7.1, 2.8.3, 2.9.4, 2.10.2, 2.11.3 and earlier.
Is there a patch available for CVE-2014-7819?
Yes, patches are included in the updated versions of Sprockets mentioned in the fix section.