Vulnerabilities > Asset Pipeline Project > Asset Pipeline > 3.0.5

DATE CVE VULNERABILITY TITLE RISK
2018-12-20 CVE-2018-1000817 Path Traversal vulnerability in Asset Pipeline Project Asset-Pipeline
Asset Pipeline Grails Plugin Asset-pipeline plugin version Prior to 2.14.1.1, 2.15.1 and 3.0.6 contains a Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in Download .class files and any arbitrary file.
network
low complexity
asset-pipeline-project CWE-22
5.0