Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-0899

Опубликовано: 31 авг. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Средний

Описание

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:*
Версия до 2.6.12 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.1081
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-150
CWE-94

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

CVSS3: 4.3
redhat
почти 9 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

CVSS3: 9.8
debian
почти 9 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously craft ...

CVSS3: 9.8
github
около 4 лет назад

RubyGems Code Injection vulnerability

oracle-oval
больше 8 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS

Процентиль: 95%
0.1081
Средний

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-150
CWE-94