Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-8324

Опубликовано: 05 мар. 2019
Источник: redhat
CVSS3: 7.2

Описание

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

A flaw was found in RubyGems. A crafted gem with a multi-line name is not handled correctly allowing an attacker to inject arbitrary code to the stub line of gemspec. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rubygemsNot affected
Red Hat Software Collectionsrh-ruby26-rubyNot affected
CloudForms Management Engine 5.10cfmeFixedRHSA-2019:142911.06.2019
CloudForms Management Engine 5.10cfme-amazon-smartstateFixedRHSA-2019:142911.06.2019
CloudForms Management Engine 5.10cfme-applianceFixedRHSA-2019:142911.06.2019
CloudForms Management Engine 5.10cfme-gemsetFixedRHSA-2019:142911.06.2019
CloudForms Management Engine 5.10rubyFixedRHSA-2019:142911.06.2019
Red Hat Enterprise Linux 7rubyFixedRHSA-2019:123515.05.2019
Red Hat Enterprise Linux 7.4 Advanced Update SupportrubyFixedRHSA-2020:276930.06.2020
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportrubyFixedRHSA-2020:276930.06.2020

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1692520rubygems: Installing a malicious gem may lead to arbitrary code execution

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
nvd
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
debian
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...

rocky
почти 6 лет назад

Important: ruby:2.5 security update

CVSS3: 8.8
github
почти 6 лет назад

Code injection in RubyGems

7.2 High

CVSS3