Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mw8-j583-vqfg

Опубликовано: 23 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

RubyGems passenger gem allows remote attackers to delete files

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

Affects both open source and Enterprise versions (4.0.0.beta1, 4.0.0.beta2).

Пакеты

Наименование

passenger

rubygems
Затронутые версииВерсия исправления

< 4.0.0.rc4

4.0.0.rc4

EPSS

Процентиль: 79%
0.01273
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

redhat
почти 13 лет назад

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

CVSS3: 7.5
nvd
около 6 лет назад

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.

CVSS3: 7.5
debian
около 6 лет назад

RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to dele ...

EPSS

Процентиль: 79%
0.01273
Низкий

7.5 High

CVSS3

Дефекты

CWE-20