sprockets
Rack-based asset packaging system
Activity
- Latest release
- 2w ago
- Total releases
- 120
- Cadence
- ~24 days
- Last 12 months
- 3
Reach
- Downloads
- 614.3M
- Stars
- 986
Details
- License
- MIT
- First release
- Feb 09, 2009
| Version | Released | |
|---|---|---|
4.4.1
patch
|
4.4.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
4.4.0
minor
|
4.4.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
4.3.0
minor
|
4.3.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
4.2.2
patch
|
4.2.2
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
3.7.5
patch
|
3.7.5
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
3.7.4
patch
|
3.7.4
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
3.7.3
patch
|
3.7.3
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
4.2.1
patch
|
4.2.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.2.0
minor
|
4.2.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.1.1
patch
|
4.1.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.1.0
minor
|
4.1.0
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.0.3
patch
|
4.0.3
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.0.2
patch
|
4.0.2
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.0.1
patch
|
4.0.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.0.0
major
|
4.0.0
major
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.0.0.beta10
pre
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
4.0.0.beta10
pre
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.0.0.beta9
pre
|
4.0.0.beta9
pre
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.0.0.beta8
pre
|
4.0.0.beta8
pre
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
3.7.2
patch
|
3.7.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.12.5
patch
|
2.12.5
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
4.0.0.beta7
pre
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
4.0.0.beta7
pre
Dependencies (20)
+ 12 more
Changelog
Compare changes
|
|
4.0.0.beta6
pre
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
4.0.0.beta6
pre
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
4.0.0.beta5
pre
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
4.0.0.beta5
pre
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
3.7.1
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.7.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
4.0.0.beta4
pre
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
4.0.0.beta4
pre
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
4.0.0.beta3
pre
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
4.0.0.beta3
pre
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.7.0
minor
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.7.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.6.3
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.6.3
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.6.2
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.6.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.6.1
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.6.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.6.0
minor
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.6.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
4.0.0.beta2
pre
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
4.0.0.beta2
pre
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
4.0.0.beta1
pre
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
4.0.0.beta1
pre
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
3.5.2
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.5.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.5.1
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.5.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.5.0
minor
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.5.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
3.4.1
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.4.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.4.0
minor
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.4.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.5
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.3.5
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.4
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.3.4
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.3
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.3.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.2
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.3.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.1
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.3.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.3.0
minor
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.3.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.12.4
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.12.4
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
3.2.0
minor
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.2.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.1.0
minor
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.1.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.0.3
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.0.2
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
3.0.1
patch
1 CVE
CVE-2018-3760
GHSA-pr3h-jjhj-573x
Jun 20, 2018
Sprockets path traversal leads to information leak
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. Workaround:In Rails applications, work around this issue, set This work around will not be possible in all hosting environments and upgrading is advised. Affected versions
3.0.0
3.0.1
3.0.2
3.0.3
3.1.0
3.2.0
3.3.0
3.3.1
3.3.2
3.3.3
3.3.4
3.3.5
+ 76 more Show less
3.4.0
3.4.1
3.5.0
3.5.1
3.5.2
3.6.0
3.6.1
3.6.2
3.6.3
3.7.0
3.7.1
4.0.0.beta1
4.0.0.beta2
4.0.0.beta3
4.0.0.beta4
4.0.0.beta5
4.0.0.beta6
4.0.0.beta7
0.9.0
0.9.1
1.0.0
1.0.1
1.0.2
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.1.0
2.1.0.beta
2.1.1
2.1.2
2.1.3
2.1.4
2.10.0
2.10.1
2.10.2
2.11.0
2.11.3
2.12.0
2.12.1
2.12.2
2.12.3
2.12.4
2.2.0
2.2.0.beta
2.2.1
2.2.2
2.2.3
2.3.0
2.3.0.beta
2.3.1
2.3.2
2.3.3
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.5.0
2.5.1
2.6.0
2.6.1
2.7.0
2.7.1
2.8.0
2.8.1
2.8.2
2.8.3
2.9.0
2.9.2
2.9.3
2.9.4
Fixed in
2.12.5
3.7.2
4.0.0.beta8
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|