Lucene search

K
cveRedhatCVE-2014-7819
HistoryNov 08, 2014 - 11:55 a.m.

CVE-2014-7819

2014-11-0811:55:03
CWE-22
redhat
web.nvd.nist.gov
66
cve
directory traversal
sprockets
ruby on rails
security vulnerability

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

74.4%

Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a …/ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.

Affected configurations

Nvd
Node
sprockets_projectsprocketsRange2.0.02.0.5
OR
sprockets_projectsprocketsRange2.1.02.1.4
OR
sprockets_projectsprocketsRange2.2.02.2.3
OR
sprockets_projectsprocketsRange2.3.02.3.3
OR
sprockets_projectsprocketsRange2.4.02.4.6
OR
sprockets_projectsprocketsRange2.5.02.5.1
OR
sprockets_projectsprocketsRange2.7.02.7.1
OR
sprockets_projectsprocketsRange2.8.02.8.3
OR
sprockets_projectsprocketsRange2.9.02.9.4
OR
sprockets_projectsprocketsRange2.10.02.10.2
OR
sprockets_projectsprocketsRange2.11.02.11.3
OR
sprockets_projectsprocketsRange2.12.02.12.3
OR
sprockets_projectsprocketsMatch2.6.0
OR
sprockets_projectsprocketsMatch3.0.0beta1
OR
sprockets_projectsprocketsMatch3.0.0beta2
VendorProductVersionCPE
sprockets_projectsprockets*cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*
sprockets_projectsprockets2.6.0cpe:2.3:a:sprockets_project:sprockets:2.6.0:*:*:*:*:*:*:*
sprockets_projectsprockets3.0.0cpe:2.3:a:sprockets_project:sprockets:3.0.0:beta1:*:*:*:*:*:*
sprockets_projectsprockets3.0.0cpe:2.3:a:sprockets_project:sprockets:3.0.0:beta2:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.6

Confidence

Low

EPSS

0.004

Percentile

74.4%