VDB
Sign up
HIGH7.5

GHSA-pr3h-jjhj-573x

Sprockets path traversal leads to information leak

Quick fix

GHSA-pr3h-jjhj-573x — sprockets: upgrade to the fixed version with the command below.

bundle update sprockets

Details

Specially crafted requests can be used to access files that exist on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately. ### Workaround: In Rails applications, work around this issue, set `config.assets.compile = false` and `config.public_file_server.enabled = true` in an initializer and precompile the assets.

This work around will not be possible in all hosting environments and upgrading is advised.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sprockets
Introduced in: 3.0.0Fixed in: 3.7.2
Fixbundle update sprockets
RubyGems/sprockets
Introduced in: 4.0.0.beta1Fixed in: 4.0.0.beta8
Fixbundle update sprockets
RubyGems/sprockets
Introduced in: 0Fixed in: 2.12.5
Fixbundle update sprockets

References