CVE-2014-7819
Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.89%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.html
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJ
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJ
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.html
- http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.html
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJ
- https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJ
JSON original (NVD)
Mostrar
{
"id": "CVE-2014-7819",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-11-08T11:55:03.023",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJ",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJ",
"tags": [
"Third Party Advisory"
],
"source": "secalert@redhat.com"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00103.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00105.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00110.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://groups.google.com/forum/message/raw?msg=rubyonrails-security/doAVp0YaTqY/aHFngBqNBoAJ",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://groups.google.com/forum/message/raw?msg=rubyonrails-security/wQBeGXqGs3E/JqUMB6fhh3gJ",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple directory traversal vulnerabilities in server.rb in Sprockets before 2.0.5, 2.1.x before 2.1.4, 2.2.x before 2.2.3, 2.3.x before 2.3.3, 2.4.x before 2.4.6, 2.5.x before 2.5.1, 2.6.x and 2.7.x before 2.7.1, 2.8.x before 2.8.3, 2.9.x before 2.9.4, 2.10.x before 2.10.2, 2.11.x before 2.11.3, 2.12.x before 2.12.3, and 3.x before 3.0.0.beta.3, as distributed with Ruby on Rails 3.x and 4.x, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with (1) double slashes or (2) URL encoding."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de salto de directorio en server.rb en Sprockets anterior a 2.0.5, 2.1.x anterior a 2.1.4, 2.2.x anterior a 2.2.3, 2.3.x anterior a 2.3.3, 2.4.x anterior a 2.4.6, 2.5.x anterior a 2.5.1, 2.6.x y 2.7.x anterior a 2.7.1, 2.8.x anterior a 2.8.3, 2.9.x anterior a 2.9.4, 2.10.x anterior a 2.10.2, 2.11.x anterior a 2.11.3, 2.12.x anterior a 2.12.3, y 3.x anterior a 3.0.0.beta.3, distribuido con Ruby on Rails 3.x y 4.x, permiten a atacantes remotos determinar la existencia de ficheros fuera del root de la aplicación a través de una secuencia ../ (punto punto barra) con (1) barras dobles o (2) codificación de URL."
}
],
"lastModified": "2026-06-17T00:15:45.130",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "36F5A38C-B51C-4455-80B2-3FA89022C72B",
"versionEndExcluding": "2.0.5",
"versionStartIncluding": "2.0.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B8177C76-1C51-41E2-9647-107A76D9A9C0",
"versionEndExcluding": "2.1.4",
"versionStartIncluding": "2.1.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "328E446A-05ED-4B23-9027-BC43A529C1AA",
"versionEndExcluding": "2.2.3",
"versionStartIncluding": "2.2.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "659F0437-C16E-422C-89A8-448EDA78F48E",
"versionEndExcluding": "2.3.3",
"versionStartIncluding": "2.3.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02AFF247-E71C-4C01-AB2A-EAF1CF171AC0",
"versionEndExcluding": "2.4.6",
"versionStartIncluding": "2.4.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50BAFDB7-A9B8-42E7-BC49-0D38DBC1E527",
"versionEndExcluding": "2.5.1",
"versionStartIncluding": "2.5.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DDDE474C-2C05-4D15-B24F-82635B7FD896",
"versionEndExcluding": "2.7.1",
"versionStartIncluding": "2.7.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D4C63A3-F044-49CD-8D72-D8614C359250",
"versionEndExcluding": "2.8.3",
"versionStartIncluding": "2.8.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7774FEE9-5ED9-4976-B363-38D838B8BA57",
"versionEndExcluding": "2.9.4",
"versionStartIncluding": "2.9.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7660A259-00F1-4CB6-AAE6-85D769DB4A64",
"versionEndExcluding": "2.10.2",
"versionStartIncluding": "2.10.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "70228E9F-071E-45B6-9FBA-FE85DB04806E",
"versionEndExcluding": "2.11.3",
"versionStartIncluding": "2.11.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EA983B03-4446-4FE4-8EC7-DAFC9498CE6D",
"versionEndExcluding": "2.12.3",
"versionStartIncluding": "2.12.0"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:2.6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8632528E-DF46-47BC-A229-E773D0CA4EC3"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:3.0.0:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E99F6172-6BF6-4FD1-BA63-1A9A0244FBD9"
},
{
"criteria": "cpe:2.3:a:sprockets_project:sprockets:3.0.0:beta2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84D71F8E-38B6-4E96-B745-3D19DC64504D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}