Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76wm-422q-92mq

Опубликовано: 20 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Code injection in RubyGems

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

Пакеты

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

>= 2.6.0, < 2.7.9

2.7.9

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.2

3.0.2

EPSS

Процентиль: 65%
0.00511
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 7.2
redhat
больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
nvd
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
debian
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...

rocky
почти 6 лет назад

Important: ruby:2.5 security update

EPSS

Процентиль: 65%
0.00511
Низкий

8.8 High

CVSS3

Дефекты

CWE-94