Description
All previously released versions of Sprockets (4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower), the software that powers the Rails asset pipeline, contain a directory traversal vulnerability.
Remediation
All users running an affected release should either upgrade or use one of the work arounds immediately.
References
Rails Asset Pipeline Directory Traversal Vulnerability (CVE-2018-3760)
Related Vulnerabilities
WordPress Plugin Ajax Store Locator Directory Traversal (1.2.0)
WordPress 4.2.x Multiple Vulnerabilities (4.2 - 4.2.34)
WordPress 6.3.x Multiple Vulnerabilities (6.3 - 6.3.4)
WordPress Plugin WP Support Plus Responsive Ticket System Multiple Vulnerabilities (4.1)
WordPress Plugin Advanced Dewplayer Directory Traversal (1.2)