Описание
Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| jekyll | fixed | 3.8.3+dfsg-3.1 | package | |
| jekyll | no-dsa | stretch | package |
Примечания
https://github.com/jekyll/jekyll/pull/7224
https://jekyllrb.com/news/2018/09/19/security-fixes-for-3-6-3-7-3-8/
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 7 лет назад
Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.
CVSS3: 7.5
nvd
больше 7 лет назад
Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.
CVSS3: 7.5
github
больше 7 лет назад
Jekyll allows attackers to access arbitrary files by specifying a symlink