Vulnerabilities > Asset Pipeline Project

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-1000817 Path Traversal vulnerability in Asset Pipeline Project Asset-Pipeline
Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in Download .class files and any arbitrary file.
network
low complexity
asset-pipeline-project CWE-22
7.5
2018-09-28 CVE-2018-17605 Path Traversal vulnerability in Asset Pipeline Project Asset-Pipeline
An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails.
network
low complexity
asset-pipeline-project CWE-22
7.5