Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g98m-96g9-wfjq

Опубликовано: 10 мая 2021
Источник: github
Github: Прошло ревью
CVSS3: 7

Описание

Insecure path handling in Bundler

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

Пакеты

Наименование

bundler

rubygems
Затронутые версииВерсия исправления

>= 1.14.0, < 2.1.0

2.1.0

EPSS

Процентиль: 43%
0.00206
Низкий

7 High

CVSS3

Дефекты

CWE-427
CWE-552

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

CVSS3: 6.7
redhat
больше 7 лет назад

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

CVSS3: 7.8
nvd
около 5 лет назад

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

CVSS3: 7.8
debian
около 5 лет назад

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with ...

suse-cvrf
около 5 лет назад

Security update for rubygem-bundler

EPSS

Процентиль: 43%
0.00206
Низкий

7 High

CVSS3

Дефекты

CWE-427
CWE-552