Vulnerability Description
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sprockets Project | Sprockets | >= 2.0.0, < 2.0.5 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.htmlMailing ListThird Party Advisory
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqYThird Party Advisory
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3EThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.htmlMailing ListThird Party Advisory
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqYThird Party Advisory
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3EThird Party Advisory
FAQ
What is CVE-2014-7819?
CVE-2014-7819 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x...
How severe is CVE-2014-7819?
CVE-2014-7819 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-7819?
Check the references section above for vendor advisories and patch information. Affected products include: Sprockets Project Sprockets.