Описание
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.
A flaw was found in RubyGems. A crafted gem with a multi-line name is not handled correctly allowing an attacker to inject arbitrary code to the stub line of gemspec. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | rubygems | Not affected | ||
Red Hat Software Collections | rh-ruby26-ruby | Not affected | ||
CloudForms Management Engine 5.10 | cfme | Fixed | RHSA-2019:1429 | 11.06.2019 |
CloudForms Management Engine 5.10 | cfme-amazon-smartstate | Fixed | RHSA-2019:1429 | 11.06.2019 |
CloudForms Management Engine 5.10 | cfme-appliance | Fixed | RHSA-2019:1429 | 11.06.2019 |
CloudForms Management Engine 5.10 | cfme-gemset | Fixed | RHSA-2019:1429 | 11.06.2019 |
CloudForms Management Engine 5.10 | ruby | Fixed | RHSA-2019:1429 | 11.06.2019 |
Red Hat Enterprise Linux 7 | ruby | Fixed | RHSA-2019:1235 | 15.05.2019 |
Red Hat Enterprise Linux 7.4 Advanced Update Support | ruby | Fixed | RHSA-2020:2769 | 30.06.2020 |
Red Hat Enterprise Linux 7.4 Telco Extended Update Support | ruby | Fixed | RHSA-2020:2769 | 30.06.2020 |
Показывать по
Дополнительная информация
Статус:
7.2 High
CVSS3
Связанные уязвимости
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...
7.2 High
CVSS3