Vulnerability Bulletins

DSA-4242 ruby-sprockets - security update

   
Affected software Debian
 
Orange Tsai discovered a path traversal flaw in ruby-sprockets, aRack-based asset packaging system. A remote attacker can take advantageof this flaw to read arbitrary files outside an applications rootdirectory via specially crafted requests, when the Sprockets server isused in production.

More info:

https://www.debian.org/security/2018/dsa-4242