{"id":"MGASA-2015-0074","summary":"Updated ruby-sprockets packages fix CVE-2014-7819","details":"Updated ruby-sprockets packages fix security vulnerabilities:\n\nMultiple directory traversal vulnerabilities in server.rb in Sprockets 2.12.x\nbefore 2.12.3, allow remote attackers to determine the existence of files\noutside the application root via a ../ (dot dot slash) sequence with double\nslashes or URL encoding (CVE-2014-7819).\n","modified":"2026-04-16T01:47:24.304146441Z","published":"2015-02-19T14:43:07Z","upstream":["CVE-2014-7819"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0074.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=14664"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-updates/2014-11/msg00111.html"}],"affected":[{"package":{"name":"ruby-sprockets","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/ruby-sprockets?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.10.0-4.1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0074.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}