Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-3760

50
FAUCET Score

CVE-2018-3760 is an information leak vulnerability in Sprockets, affecting versions 4.0.0.beta7 and lower, 3.7.1 and lower, and 2.12.4 and lower, including deployments on Debian and Red Hat. This flaw allows attackers to access files outside the application's root directory via specially crafted requests when the Sprockets server is used in production. Rated with a CVSS score of 7.5 (HIGH), it poses a significant risk due to its network-based attack vector and high confidentiality impact. While not in the KEV catalog, its high EPSS score and available Nuclei templates indicate a strong likelihood of exploitation, further evidenced by community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
4.5CPE matchmatch criteria
cpe:2.3:a:redhat:cloudforms:4.5:*:*:*:*:*:*:*
4.6CPE matchmatch criteria
cpe:2.3:a:redhat:cloudforms:4.6:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
6.7CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:6.7:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
26.72%
Probability of exploitation in next 30 days
EPSS Percentile
97.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
Nuclei: CVE-2018-3760 · Apr 5, 2020
This CVE's current EPSS score of 0.2672 is in the 96th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (28)

redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-ror50-rubygem-sprockets-0:3.7.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-ror42-rubygem-sprockets-0:3.2.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-ror50-rubygem-sprockets-0:3.7.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.8Fixed in: ansible-tower-0:3.1.8-1.el7at
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.8Fixed in: cfme-0:5.8.5.1-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.8Fixed in: cfme-appliance-0:5.8.5.1-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.8Fixed in: cfme-gemset-0:5.8.5.1-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.8Fixed in: rh-postgresql95-postgresql-pglogical-0:1.2.1-2.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-0:5.9.4.7-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-amazon-smartstate-0:5.9.4.7-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-appliance-0:5.9.4.7-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-gemset-0:5.9.4.7-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: rh-postgresql95-postgresql-pglogical-0:2.1.0-4.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: rh-ruby23-rubygem-redhat_access_cfme-0:2.0.3-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-ror42-rubygem-sprockets-0:3.2.0-5.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-ror50-rubygem-sprockets-0:3.7.1-2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-ror42-rubygem-sprockets-0:3.2.0-5.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-ror50-rubygem-sprockets-0:3.7.1-2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-ror42-rubygem-sprockets-0:3.2.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-ror50-rubygem-sprockets-0:3.7.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-ror42-rubygem-sprockets-0:3.2.0-5.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-ror50-rubygem-sprockets-0:3.7.1-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-ror42-rubygem-sprockets-0:3.2.0-5.el7
View patch
rubygemspatch availablevia ghsa
Product: sprocketsFixed in: 2.12.5
rubygemspatch availablevia ghsa
Product: sprocketsFixed in: 3.7.2
rubygemspatch availablevia ghsa
Product: sprocketsFixed in: 4.0.0.beta8
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 1.3Fixed in: ruby193-rubygem-sprockets
redhatend of lifevia redhat_api
Product: Red Hat Subscription Asset ManagerFixed in: ruby193-rubygem-sprockets

Vendor Advisories (2)

rubygemsGHSA-pr3h-jjhj-573xhigh

Sprockets path traversal leads to information leak

Jun 20, 2018
redhatCVE-2018-3760Important

rubygem-sprockets: Path traversal in forbidden_request?() can allow remote attackers to read arbitrary files

Jun 20, 2018

References

access.redhat.com / errata/RHSA-2018:2244
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2245
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2561
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2745
Third Party Advisory
github.com / rails/sprockets/commit/c09131cf5b2c479263939c8582e22b98ed616c5fhttps://github.com/rails/sprockets/commit/9c34fa05900b968d74f08ccf40917848a7be9441https://github.com/rails/sprockets/commit/18b8a7f07a50c245e9aee7854ecdbe606bbd8bb5
Broken Link
groups.google.com / d/msg/rubyonrails-security/ft_J--l55fM/7roDfQ50BwAJ
PatchThird Party Advisory
debian.org / security/2018/dsa-4242
Third Party Advisory