CVE-2018-3760

Scores

EPSS

0.938high93.8%
0%20%40%60%80%100%

Percentile: 93.8%

CVSS

7.5high3.x
0246810

CVSS Score: 7.5/10

All CVSS Scores

CVSS 3.x
7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS 2.0
5.0

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Description

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application’s root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

astradebiannvdredhatubuntu

CWEs

CWE-22

Related Vulnerabilities

Exploits

Exploit ID: CVE-2018-3760

Source: github-poc

URL: https://github.com/wudidwo/CVE-2018-3760-poc

Recommendations

Source: nvd

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2018:2245

Source: nvd

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

URL: https://access.redhat.com/errata/RHSA-2018:2244

Vulnerable Software (48)

Type: Configuration

Product: ansible-tower

Operating System: rhel

Trait:
{  "fixed": "3.1.8-1.el7at"}

Source: redhat

Type: Configuration

Product: cfme

Operating System: rhel

Trait:
{  "fixed": "5.8.5.1-1.el7cf"}

Source: redhat

Type: Configuration

Product: cfme

Operating System: rhel

Trait:
{  "fixed": "5.9.4.7-1.el7cf"}

Source: redhat

Type: Configuration

Product: cfme-amazon-smartstate

Operating System: rhel

Trait:
{  "fixed": "5.9.4.7-1.el7cf"}

Source: redhat

Type: Configuration

Product: cfme-appliance

Operating System: rhel

Trait:
{  "fixed": "5.8.5.1-1.el7cf"}

Source: redhat

Type: Configuration

Product: cfme-appliance

Operating System: rhel

Trait:
{  "fixed": "5.9.4.7-1.el7cf"}

Source: redhat

Type: Configuration

Product: cfme-gemset

Operating System: rhel

Trait:
{  "fixed": "5.8.5.1-1.el7cf"}

Source: redhat

Type: Configuration

Product: cfme-gemset

Operating System: rhel

Trait:
{  "fixed": "5.9.4.7-1.el7cf"}

Source: redhat

Type: Configuration

Product: rh-postgresql95-postgresql-pglogical

Operating System: rhel

Trait:
{  "fixed": "1.2.1-2.el7cf"}

Source: redhat

Type: Configuration

Product: rh-postgresql95-postgresql-pglogical

Operating System: rhel

Trait:
{  "fixed": "2.1.0-4.el7cf"}

Source: redhat

Type: Configuration

Product: rh-ror42-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.2.0-5.el6"}

Source: redhat

Type: Configuration

Product: rh-ror42-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.2.0-5.el6"}

Source: redhat

Type: Configuration

Product: rh-ror42-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.2.0-5.el7"}

Source: redhat

Type: Configuration

Product: rh-ror42-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.2.0-5.el7"}

Source: redhat

Type: Configuration

Product: rh-ror42-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.2.0-5.el7"}

Source: redhat

Type: Configuration

Product: rh-ror42-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.2.0-5.el7"}

Source: redhat

Type: Configuration

Product: rh-ror50-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.7.1-2.el6"}

Source: redhat

Type: Configuration

Product: rh-ror50-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.7.1-2.el7"}

Source: redhat

Type: Configuration

Product: rh-ror50-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.7.1-2.el7"}

Source: redhat

Type: Configuration

Product: rh-ror50-rubygem-sprockets

Operating System: rhel

Trait:
{  "fixed": "3.7.1-2.el7"}

Source: redhat