CVE-2018-3760

Description

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an applications root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
93.887

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM Aspera Shares 1.10.1Windows
Vulnerabilities CVE-2018-3760 are fixed in Ruby-sprockets 2.12.5Windows
Vulnerabilities CVE-2018-3760 are fixed in Ruby-sprockets 3.7.2Windows
Vulnerabilities CVE-2018-3760 are fixed in Ruby-sprockets 4.0.0Windows
ruby-sprockets security update(DSA-4242-1) ruby-sprockets_3.7.0-1+deb9u1_all.debLinux
Vulnerabilities CVE-2018-3760 are fixed in Ruby-sprockets for Linux 2.12.5Linux
Vulnerabilities CVE-2018-3760 are fixed in Ruby-sprockets for Linux 3.7.2Linux
Vulnerabilities CVE-2018-3760 are fixed in Ruby-sprockets for Linux 4.0.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234