File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ ---
2+ gem : sprockets
3+ cve : 2018-3760
4+ url : https://groups.google.com/forum/#!topic/ruby-security-ann/2S9Pwz2i16k
5+ title : Path Traversal in Sprockets
6+ date : 2018-06-19
7+ description : |
8+ Specially crafted requests can be used to access files that exist on
9+ the filesystem that is outside an application's root directory, when the
10+ Sprockets server is used in production.
11+
12+ All users running an affected release should either upgrade or use one of the work arounds immediately.
13+
14+ Workaround:
15+ In Rails applications, work around this issue, set `config.assets.compile = false` and
16+ `config.public_file_server.enabled = true` in an initializer and precompile the assets.
17+
18+ This work around will not be possible in all hosting environments and upgrading is advised.
19+
20+ patched_versions :
21+ - " >= 2.12.5, < 3.0.0"
22+ - " >= 3.7.2, < 4.0.0"
23+ - " >= 4.0.0.beta8"
You can’t perform that action at this time.
0 commit comments