VYPR

RubyGems package

sprockets

pkg:gem/sprockets

Vulnerabilities (2)

  • CVE-2018-3760HigJun 26, 2018
    affected >= 3.0.0, < 3.7.2fixed 3.7.2

    There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Spr

  • CVE-2014-7819Nov 8, 2014
    affected < 2.0.5fixed 2.0.5

    Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.1