5.0.8
9 years ago
15 days ago
Known vulnerabilities in the com.bertramlabs.plugins:asset-pipeline-servlet package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
com.bertramlabs.plugins:asset-pipeline-servlet is an asset pipeline for the jvm Affected versions of this package are vulnerable to Directory Traversal that allows attackers to access and download arbitrary files, including .class files, by passing the path to each file in a GET request. NOTE: This vulnerability is only exploitable for applications deployed with Jetty. How to fix Directory Traversal? Upgrade | [,2.14.1)[3.0.0,3.0.6) |