Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 20

Количество 20

fstec логотип

BDU:2024-02457

больше 2 лет назад

Уязвимость встроенного генератора документации RDoc для языка программирования Ruby, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.5
EPSS: Низкий
ubuntu логотип

CVE-2024-27281

около 2 лет назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
redhat логотип

CVE-2024-27281

больше 2 лет назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
nvd логотип

CVE-2024-27281

около 2 лет назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
msrc логотип

CVE-2024-27281

около 2 лет назад

CVSS3: 4.5
EPSS: Низкий
debian логотип

CVE-2024-27281

около 2 лет назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in ...

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-592j-995h-p23j

больше 2 лет назад

RDoc RCE vulnerability with .rdoc_options

CVSS3: 4.5
EPSS: Низкий
rocky логотип

RLSA-2024:3671

около 2 лет назад

Moderate: ruby:3.3 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2024:3670

около 2 лет назад

Moderate: ruby:3.3 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2024:3668

около 2 лет назад

Moderate: ruby:3.1 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2024:3546

около 2 лет назад

Moderate: ruby:3.1 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3671

около 2 лет назад

ELSA-2024-3671: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3670

около 2 лет назад

ELSA-2024-3670: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3668

около 2 лет назад

ELSA-2024-3668: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3546

около 2 лет назад

ELSA-2024-3546: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:4499

около 2 лет назад

Moderate: ruby security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4499

около 2 лет назад

ELSA-2024-4499: ruby security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:3500

около 1 года назад

Moderate: ruby:3.0 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3838

около 2 лет назад

ELSA-2024-3838: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3500

около 2 лет назад

ELSA-2024-3500: ruby:3.0 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-02457

Уязвимость встроенного генератора документации RDoc для языка программирования Ruby, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.5
2%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
2%
Низкий
около 2 лет назад
redhat логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
2%
Низкий
около 2 лет назад
msrc логотип
CVSS3: 4.5
2%
Низкий
около 2 лет назад
debian логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in ...

CVSS3: 4.5
2%
Низкий
около 2 лет назад
github логотип
GHSA-592j-995h-p23j

RDoc RCE vulnerability with .rdoc_options

CVSS3: 4.5
2%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2024:3671

Moderate: ruby:3.3 security, bug fix, and enhancement update

около 2 лет назад
rocky логотип
RLSA-2024:3670

Moderate: ruby:3.3 security, bug fix, and enhancement update

около 2 лет назад
rocky логотип
RLSA-2024:3668

Moderate: ruby:3.1 security, bug fix, and enhancement update

около 2 лет назад
rocky логотип
RLSA-2024:3546

Moderate: ruby:3.1 security, bug fix, and enhancement update

около 2 лет назад
oracle-oval логотип
ELSA-2024-3671

ELSA-2024-3671: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2024-3670

ELSA-2024-3670: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2024-3668

ELSA-2024-3668: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2024-3546

ELSA-2024-3546: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

около 2 лет назад
rocky логотип
RLSA-2024:4499

Moderate: ruby security update

около 2 лет назад
oracle-oval логотип
ELSA-2024-4499

ELSA-2024-4499: ruby security update (MODERATE)

около 2 лет назад
rocky логотип
RLSA-2024:3500

Moderate: ruby:3.0 security update

около 1 года назад
oracle-oval логотип
ELSA-2024-3838

ELSA-2024-3838: ruby security update (MODERATE)

около 2 лет назад
oracle-oval логотип
ELSA-2024-3500

ELSA-2024-3500: ruby:3.0 security update (MODERATE)

около 2 лет назад

Уязвимостей на страницу