CVE-2018-3760

High PUBLISHED

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially...

HackerOne · Sprockets

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
7.5 High

At a Glance

There is an information leak vulnerability in Sprockets. Versions Affected: 4.0.0.beta7 and lower, 3.7.1 and lower, 2.12.4 and lower. Specially crafted requests can be used to access files that exists on the filesystem that is outside an application's root directory, when the Sprockets server is used in production. All users running an affected release should either upgrade or use one of the work arounds immediately.

nuclei_scanner
CVE Published
Jun 26, 2018
Exploitation Reported
Apr 27, 2025
CVSS
7.5 High
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
HackerOne
Sprockets

4.0.0.beta8, 3.7.2, 2.12.5

Affected

CVE References

  • RHSA-2018:2745 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:2745
  • RHSA-2018:2244 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:2244
  • RHSA-2018:2561 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:2561
  • RHSA-2018:2245 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:2245
  • DSA-4242 debian.org · Vendor Advisory https://www.debian.org/security/2018/dsa-4242
Show 2 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.