Описание
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
A directory and symbolic link traversal flaw was found in the way rubyzip gem extracts zip files. An attacker, with access to a privileged application capable of extracting zip files, could use this flaw to write new files to arbitrary paths, accessible by the aforementioned privileged application.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Quickstart Cloud Installer 1 | tfm-rubygem-rubyzip | Will not fix | ||
| CloudForms Management Engine 5.9 | ansible-tower | Fixed | RHSA-2018:3466 | 05.11.2018 |
| CloudForms Management Engine 5.9 | cfme | Fixed | RHSA-2018:3466 | 05.11.2018 |
| CloudForms Management Engine 5.9 | cfme-amazon-smartstate | Fixed | RHSA-2018:3466 | 05.11.2018 |
| CloudForms Management Engine 5.9 | cfme-appliance | Fixed | RHSA-2018:3466 | 05.11.2018 |
| CloudForms Management Engine 5.9 | cfme-gemset | Fixed | RHSA-2018:3466 | 05.11.2018 |
Показывать по
Дополнительная информация
Статус:
4.8 Medium
CVSS3
Связанные уязвимости
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem..
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Tra ...
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
4.8 Medium
CVSS3