Описание
chef/travis-cookbooks/ci_environment/perlbrew/recipes/default.rb in the ciborg gem 3.0.0 for Ruby allows local users to write to arbitrary files and gain privileges via a symlink attack on /tmp/perlbrew-installer.
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:ciborg_project:ciborg:3.0.0:*:*:*:*:ruby:*:*
EPSS
Процентиль: 16%
0.00052
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-20
Связанные уязвимости
CVSS3: 5.5
github
больше 7 лет назад
Ciborg gem for Ruby allows local users to write files and gain privileges via Symlink
EPSS
Процентиль: 16%
0.00052
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-20