Логотип exploitDog
bind:"CVE-2024-27281"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-27281"

Количество 20

Количество 20

ubuntu логотип

CVE-2024-27281

больше 1 года назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
redhat логотип

CVE-2024-27281

больше 1 года назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
nvd логотип

CVE-2024-27281

больше 1 года назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
msrc логотип

CVE-2024-27281

больше 1 года назад

CVSS3: 4.5
EPSS: Низкий
debian логотип

CVE-2024-27281

больше 1 года назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in ...

CVSS3: 4.5
EPSS: Низкий
github логотип

GHSA-592j-995h-p23j

больше 1 года назад

RDoc RCE vulnerability with .rdoc_options

CVSS3: 4.5
EPSS: Низкий
fstec логотип

BDU:2024-02457

больше 1 года назад

Уязвимость встроенного генератора документации RDoc для языка программирования Ruby, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.5
EPSS: Низкий
rocky логотип

RLSA-2024:3671

больше 1 года назад

Moderate: ruby:3.3 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2024:3670

больше 1 года назад

Moderate: ruby:3.3 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2024:3668

больше 1 года назад

Moderate: ruby:3.1 security, bug fix, and enhancement update

EPSS: Низкий
rocky логотип

RLSA-2024:3546

больше 1 года назад

Moderate: ruby:3.1 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3671

больше 1 года назад

ELSA-2024-3671: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3670

больше 1 года назад

ELSA-2024-3670: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3668

больше 1 года назад

ELSA-2024-3668: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3546

больше 1 года назад

ELSA-2024-3546: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:4499

больше 1 года назад

Moderate: ruby security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4499

больше 1 года назад

ELSA-2024-4499: ruby security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:3500

7 месяцев назад

Moderate: ruby:3.0 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3838

больше 1 года назад

ELSA-2024-3838: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3500

больше 1 года назад

ELSA-2024-3500: ruby:3.0 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
2%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
2%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
2%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 4.5
2%
Низкий
больше 1 года назад
debian логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in ...

CVSS3: 4.5
2%
Низкий
больше 1 года назад
github логотип
GHSA-592j-995h-p23j

RDoc RCE vulnerability with .rdoc_options

CVSS3: 4.5
2%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-02457

Уязвимость встроенного генератора документации RDoc для языка программирования Ruby, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.5
2%
Низкий
больше 1 года назад
rocky логотип
RLSA-2024:3671

Moderate: ruby:3.3 security, bug fix, and enhancement update

больше 1 года назад
rocky логотип
RLSA-2024:3670

Moderate: ruby:3.3 security, bug fix, and enhancement update

больше 1 года назад
rocky логотип
RLSA-2024:3668

Moderate: ruby:3.1 security, bug fix, and enhancement update

больше 1 года назад
rocky логотип
RLSA-2024:3546

Moderate: ruby:3.1 security, bug fix, and enhancement update

больше 1 года назад
oracle-oval логотип
ELSA-2024-3671

ELSA-2024-3671: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-3670

ELSA-2024-3670: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-3668

ELSA-2024-3668: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-3546

ELSA-2024-3546: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

больше 1 года назад
rocky логотип
RLSA-2024:4499

Moderate: ruby security update

больше 1 года назад
oracle-oval логотип
ELSA-2024-4499

ELSA-2024-4499: ruby security update (MODERATE)

больше 1 года назад
rocky логотип
RLSA-2024:3500

Moderate: ruby:3.0 security update

7 месяцев назад
oracle-oval логотип
ELSA-2024-3838

ELSA-2024-3838: ruby security update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-3500

ELSA-2024-3500: ruby:3.0 security update (MODERATE)

больше 1 года назад

Уязвимостей на страницу