Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p7f2-rr42-m9xm

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

RubyGems Improper Input Validation vulnerability

RubyGems versions 2.6.12 and earlier are vulnerable to maliciously crafted gem specifications that cause a denial of service attack against RubyGems clients who have issued a query command.

Пакеты

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

< 2.6.13

2.6.13

EPSS

Процентиль: 92%
0.09382
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

CVSS3: 4.3
redhat
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

CVSS3: 7.5
nvd
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

CVSS3: 7.5
debian
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously craft ...

oracle-oval
больше 7 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS

Процентиль: 92%
0.09382
Низкий

7.5 High

CVSS3

Дефекты

CWE-20