First published: Sat Nov 08 2014(Updated: )
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sprockets Project Sprockets | >=2.0.0<2.0.5 | |
Sprockets Project Sprockets | >=2.1.0<2.1.4 | |
Sprockets Project Sprockets | >=2.2.0<2.2.3 | |
Sprockets Project Sprockets | >=2.3.0<2.3.3 | |
Sprockets Project Sprockets | >=2.4.0<2.4.6 | |
Sprockets Project Sprockets | >=2.5.0<2.5.1 | |
Sprockets Project Sprockets | >=2.7.0<2.7.1 | |
Sprockets Project Sprockets | >=2.8.0<2.8.3 | |
Sprockets Project Sprockets | >=2.9.0<2.9.4 | |
Sprockets Project Sprockets | >=2.10.0<2.10.2 | |
Sprockets Project Sprockets | >=2.11.0<2.11.3 | |
Sprockets Project Sprockets | >=2.12.0<2.12.3 | |
Sprockets Project Sprockets | =2.6.0 | |
Sprockets Project Sprockets | =3.0.0-beta1 | |
Sprockets Project Sprockets | =3.0.0-beta2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-7819 has been classified as a moderate severity vulnerability impacting multiple versions of the Sprockets component.
To mitigate CVE-2014-7819, upgrade Sprockets to versions 2.0.5, 2.1.4, 2.2.3, 2.3.3, 2.4.6, 2.5.1, 2.7.1, 2.8.3, 2.9.4, 2.10.2, 2.11.3 or later.
Exploitation of CVE-2014-7819 could allow attackers to traverse directories and access sensitive files on the server.
CVE-2014-7819 affects Sprockets versions prior to 2.0.5, 2.1.4, 2.2.3, 2.3.3, 2.4.6, 2.5.1, 2.7.1, 2.8.3, 2.9.4, 2.10.2, 2.11.3 and earlier.
Yes, patches are included in the updated versions of Sprockets mentioned in the fix section.