CVE-2014-7819
published 2014-11-08CVE-2014-7819: Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before…
PriorityP432medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
3.86%
89.0th percentile
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ruby-sprockets | < ruby-sprockets 2.12.3-1 (bookworm) | ruby-sprockets 2.12.3-1 (bookworm) |
| sprockets_project | sprockets | — | — |
| sprockets_project | sprockets | — | — |
| sprockets_project | sprockets | >= 0 < 2.0.5 | 2.0.5 |
| sprockets_project | sprockets | >= 2.0.0 < 2.0.5 | 2.0.5 |
| sprockets_project | sprockets | >= 2.1.0 < 2.1.4 | 2.1.4 |
| sprockets_project | sprockets | >= 2.1.0 < 2.1.4 | 2.1.4 |
| sprockets_project | sprockets | >= 2.10.0 < 2.10.2 | 2.10.2 |
| sprockets_project | sprockets | >= 2.10.0 < 2.10.2 | 2.10.2 |
| sprockets_project | sprockets | >= 2.11.0 < 2.11.3 | 2.11.3 |
| sprockets_project | sprockets | >= 2.11.0 < 2.11.3 | 2.11.3 |
| sprockets_project | sprockets | >= 2.12.0 < 2.12.3 | 2.12.3 |
| sprockets_project | sprockets | >= 2.12.0 < 2.12.3 | 2.12.3 |
| sprockets_project | sprockets | >= 2.2.0 < 2.2.3 | 2.2.3 |
| sprockets_project | sprockets | >= 2.2.0 < 2.2.3 | 2.2.3 |
| sprockets_project | sprockets | >= 2.3.0 < 2.3.3 | 2.3.3 |
| sprockets_project | sprockets | >= 2.3.0 < 2.3.3 | 2.3.3 |
| sprockets_project | sprockets | >= 2.4.0 < 2.4.6 | 2.4.6 |
| sprockets_project | sprockets | >= 2.4.0 < 2.4.6 | 2.4.6 |
| sprockets_project | sprockets | >= 2.5.0 < 2.5.1 | 2.5.1 |
| sprockets_project | sprockets | >= 2.5.0 < 2.5.1 | 2.5.1 |
| sprockets_project | sprockets | >= 2.6.0 < 2.7.1 | 2.7.1 |
| sprockets_project | sprockets | >= 2.7.0 < 2.7.1 | 2.7.1 |
| sprockets_project | sprockets | >= 2.8.0 < 2.8.3 | 2.8.3 |
| sprockets_project | sprockets | >= 2.8.0 < 2.8.3 | 2.8.3 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
sprockets vulnerable to Path Traversal
osv·2017-10-24
CVE-2014-7819 [MEDIUM] sprockets vulnerable to Path Traversal
sprockets vulnerable to Path Traversal
Multiple directory traversal vulnerabilities in `server.rb` in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
GHSA
sprockets vulnerable to Path Traversal
ghsa·2017-10-24
CVE-2014-7819 [MEDIUM] CWE-22 sprockets vulnerable to Path Traversal
sprockets vulnerable to Path Traversal
Multiple directory traversal vulnerabilities in `server.rb` in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
OSV
CVE-2014-7819: Multiple directory traversal vulnerabilities in server
osv·2014-11-08·CVSS 5.0
CVE-2014-7819 [MEDIUM] CVE-2014-7819: Multiple directory traversal vulnerabilities in server
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
Red Hat
rubygem-sprockets: arbitrary file existence disclosure
vendor_redhat·2014-10-31·CVSS 5.0
CVE-2014-7819 [MEDIUM] CWE-22 rubygem-sprockets: arbitrary file existence disclosure
rubygem-sprockets: arbitrary file existence disclosure
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional info
Debian
CVE-2014-7819: ruby-sprockets - Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2....
vendor_debian·2014·CVSS 5.0
CVE-2014-7819 [MEDIUM] CVE-2014-7819: ruby-sprockets - Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2....
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
Scope: local
bookworm: resolved (fixed in 2.12.3-1)
bullseye: resolved (fixed in 2.12.3-1)
forky: resolved (fixed in 2.12.3-1)
sid: resolved (fixed in 2.12.3-1)
trixie: resolved (fixed in 2.12.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7819 rubygem-sprockets: arbitrary file existence disclosure [fedora-all]
bugzilla·2014-11-14·CVSS 5.0
CVE-2014-7819 [MEDIUM] CVE-2014-7819 rubygem-sprockets: arbitrary file existence disclosure [fedora-all]
CVE-2014-7819 rubygem-sprockets: arbitrary file existence disclosure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2014-7819 rubygem-sprockets: arbitrary file existence disclosure
bugzilla·2014-11-07·CVSS 5.0
CVE-2014-7819 [MEDIUM] CVE-2014-7819 rubygem-sprockets: arbitrary file existence disclosure
CVE-2014-7819 rubygem-sprockets: arbitrary file existence disclosure
The following Ruby on Rails issue was reported[1]:
""
Arbitrary file existence disclosure in Sprockets
There is an information leak vulnerability in Sprockets. This vulnerability
has been assigned the CVE identifier CVE-2014-7819.
Versions Affected: ALL
Not affected: NONE
Fixed Versions: 3.0.0.beta.3, 2.12.3, 2.11.3, 2.10.2, 2.9.4, 2.8.3, 2.7.1, 2.5.1, 2.4.6, 2.3.3, 2.2.3, 2.1.4, 2.0.5
Impact
Specially crafted requests can be used to determine whether a file exists on
the filesystem that is outside an application's root directory. The files will not be served, but attackers can determine whether or not the file exists.
All users running an affected release should either upgrade or use one of the work arounds immedia
http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00105.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00110.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00111.htmlhttps://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJhttps://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00103.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00105.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00110.htmlhttp://lists.opensuse.org/opensuse-updates/2014-11/msg00111.htmlhttps://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJhttps://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJ
2014-11-08
Published