Debian Security Update DSA-4242 ruby-sprockets - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,812
Reaction score
74
Credits
-1,257
Orange Tsai discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker can take advantage of this flaw to read arbitrary files outside an application's root directory via specially crafted requests, when the Sprockets server is used in production.

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top