Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gcqq-w6gr-h9j9

Опубликовано: 24 окт. 2017
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Directory traversal vulnerability in RubyZip

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses ../ pathname substrings to write arbitrary files to the filesystem.

Пакеты

Наименование

rubyzip

rubygems
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 90%
0.05924
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.

CVSS3: 7
redhat
около 9 лет назад

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.

CVSS3: 9.8
nvd
почти 9 лет назад

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.

CVSS3: 9.8
debian
почти 9 лет назад

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a ...

suse-cvrf
больше 8 лет назад

Security update for rubygem-rubyzip

EPSS

Процентиль: 90%
0.05924
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22