Vulnerabilities > Asset Pipeline Project
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-12-20 | CVE-2018-1000817 | Path Traversal vulnerability in Asset Pipeline Project Asset-Pipeline Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in Download .class files and any arbitrary file. | 7.5 |
2018-09-28 | CVE-2018-17605 | Path Traversal vulnerability in Asset Pipeline Project Asset-Pipeline An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails. | 7.5 |