Vulnerability Bulletins |
DSA-4242 ruby-sprockets - security update |
|
| Affected software | Debian |
|
Orange Tsai discovered a path traversal flaw in ruby-sprockets, aRack-based asset packaging system. A remote attacker can take advantageof this flaw to read arbitrary files outside an applications rootdirectory via specially crafted requests, when the Sprockets server isused in production. More info: https://www.debian.org/security/2018/dsa-4242 |
|






