Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-3881

Опубликовано: 04 сент. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 4.4
EPSS Низкий

Описание

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bundler:bundler:*:*:*:*:*:ruby:*:*
Версия до 2.1.0 (исключая)

EPSS

Процентиль: 43%
0.00206
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-427
CWE-427

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

CVSS3: 6.7
redhat
больше 7 лет назад

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

CVSS3: 7.8
debian
около 5 лет назад

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with ...

suse-cvrf
около 5 лет назад

Security update for rubygem-bundler

suse-cvrf
больше 5 лет назад

Security update for rubygem-bundler

EPSS

Процентиль: 43%
0.00206
Низкий

7.8 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-427
CWE-427