Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8130

Опубликовано: 29 авг. 2019
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character |.

Отчет

Red Hat CloudForms 5.10 and Red Hat Satellite 6 contains affected rake version, however, it is not vulnerable since it does not use egrep after FileList loads file with pipe-character, this makes OS injection practically impossible with it's existing Rakefile. Red Hat may update rake in future releases. The version of rubygem-rake shipped with Red Hat Gluster Storage includes the vulnerable code, but the module FileList is currently not used by the product and hence this issue has been rated as having a security impact of Low for RHGS.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5cfme-amazon-smartstateFix deferred
CloudForms Management Engine 5cfme-gemsetFix deferred
Red Hat OpenShift Container Platform 3.11fluentdNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-logging-fluentdNot affected
Red Hat Storage 3rubygem-rakeAffected
Red Hat Satellite 6.10 for RHEL 7satelliteFixedRHSA-2021:470216.11.2021
Red Hat Satellite 6.10 for RHEL 7satelliteFixedRHSA-2021:470216.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=1816270rake: OS Command Injection via egrep in Rake::FileList

EPSS

Процентиль: 33%
0.00128
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
ubuntu
почти 6 лет назад

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

CVSS3: 6.4
nvd
почти 6 лет назад

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

msrc
4 месяца назад

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

CVSS3: 6.4
debian
почти 6 лет назад

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 i ...

suse-cvrf
больше 3 лет назад

Security update for rubygem-rake

EPSS

Процентиль: 33%
0.00128
Низкий

6.4 Medium

CVSS3