Количество 12
Количество 12
CVE-2019-3881
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
CVE-2019-3881
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
CVE-2019-3881
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
CVE-2019-3881
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with ...
openSUSE-SU-2020:0861-1
Security update for rubygem-bundler
openSUSE-SU-2020:0803-1
Security update for rubygem-bundler
SUSE-SU-2020:1582-2
Security update for rubygem-bundler
SUSE-SU-2020:1582-1
Security update for rubygem-bundler
GHSA-g98m-96g9-wfjq
Insecure path handling in Bundler
BDU:2020-04070
Уязвимость менеджера управления пакетами gems проектов Ruby Bundler, связанная с использованием файлов и каталогов, доступных внешним сторонам, позволяющая нарушителю выполнить произвольный код
RLSA-2021:2588
Moderate: ruby:2.6 security, bug fix, and enhancement update
ELSA-2021-2588
ELSA-2021-2588: ruby:2.6 security, bug fix, and enhancement update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-3881 Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed. | CVSS3: 7.8 | 0% Низкий | около 5 лет назад | |
CVE-2019-3881 Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed. | CVSS3: 6.7 | 0% Низкий | больше 7 лет назад | |
CVE-2019-3881 Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed. | CVSS3: 7.8 | 0% Низкий | около 5 лет назад | |
CVE-2019-3881 Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with ... | CVSS3: 7.8 | 0% Низкий | около 5 лет назад | |
openSUSE-SU-2020:0861-1 Security update for rubygem-bundler | 0% Низкий | больше 5 лет назад | ||
openSUSE-SU-2020:0803-1 Security update for rubygem-bundler | 0% Низкий | больше 5 лет назад | ||
SUSE-SU-2020:1582-2 Security update for rubygem-bundler | 0% Низкий | больше 5 лет назад | ||
SUSE-SU-2020:1582-1 Security update for rubygem-bundler | 0% Низкий | больше 5 лет назад | ||
GHSA-g98m-96g9-wfjq Insecure path handling in Bundler | CVSS3: 7 | 0% Низкий | больше 4 лет назад | |
BDU:2020-04070 Уязвимость менеджера управления пакетами gems проектов Ruby Bundler, связанная с использованием файлов и каталогов, доступных внешним сторонам, позволяющая нарушителю выполнить произвольный код | CVSS3: 6.7 | 0% Низкий | больше 6 лет назад | |
RLSA-2021:2588 Moderate: ruby:2.6 security, bug fix, and enhancement update | больше 4 лет назад | |||
ELSA-2021-2588 ELSA-2021-2588: ruby:2.6 security, bug fix, and enhancement update (MODERATE) | больше 4 лет назад |
Уязвимостей на страницу