Описание
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
Отчет
The version of rubygem-bundler provided in 'Red Hat Gluster Storage 3' does not contain the vulnerable functionality and is not affected by this vulnerability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat 3scale API Management Platform 2 | backend | Affected | ||
Red Hat Enterprise Linux 7 | rubygem-bundler | Not affected | ||
Red Hat Enterprise Linux 8 | ruby:2.5/rubygem-bundler | Affected | ||
Red Hat Software Collections | rh-ruby23-rubygem-bundler | Not affected | ||
Red Hat Software Collections | rh-ruby24-rubygem-bundler | Not affected | ||
Red Hat Software Collections | rh-ruby25-rubygem-bundler | Will not fix | ||
Red Hat Software Collections | rh-ruby27-ruby | Not affected | ||
Red Hat Storage 3 | rubygem-bundler | Not affected | ||
Red Hat Subscription Asset Manager | ruby193-rubygem-bundler | Not affected | ||
Red Hat Subscription Asset Manager | rubygem-bundler | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.7 Medium
CVSS3
Связанные уязвимости
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with ...
EPSS
6.7 Medium
CVSS3