Логотип exploitDog
bind:"GHSA-592j-995h-p23j" OR bind:"CVE-2024-27281"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-592j-995h-p23j" OR bind:"CVE-2024-27281"

Количество 14

Количество 14

github логотип

GHSA-592j-995h-p23j

около 1 года назад

RDoc RCE vulnerability with .rdoc_options

CVSS3: 4.5
EPSS: Низкий
ubuntu логотип

CVE-2024-27281

около 1 года назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
redhat логотип

CVE-2024-27281

около 1 года назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
nvd логотип

CVE-2024-27281

около 1 года назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
EPSS: Низкий
msrc логотип

CVE-2024-27281

около 1 года назад

CVSS3: 4.5
EPSS: Низкий
debian логотип

CVE-2024-27281

около 1 года назад

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in ...

CVSS3: 4.5
EPSS: Низкий
fstec логотип

BDU:2024-02457

больше 1 года назад

Уязвимость встроенного генератора документации RDoc для языка программирования Ruby, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-3671

около 1 года назад

ELSA-2024-3671: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3670

около 1 года назад

ELSA-2024-3670: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3668

около 1 года назад

ELSA-2024-3668: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3546

около 1 года назад

ELSA-2024-3546: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4499

11 месяцев назад

ELSA-2024-4499: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3838

около 1 года назад

ELSA-2024-3838: ruby security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3500

около 1 года назад

ELSA-2024-3500: ruby:3.0 security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-592j-995h-p23j

RDoc RCE vulnerability with .rdoc_options

CVSS3: 4.5
3%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
3%
Низкий
около 1 года назад
redhat логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
3%
Низкий
около 1 года назад
nvd логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored. (When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.) The main fixed version is 6.6.3.1. For Ruby 3.0 users, a fixed version is rdoc 6.3.4.1. For Ruby 3.1 users, a fixed version is rdoc 6.4.1.1. For Ruby 3.2 users, a fixed version is rdoc 6.5.1.1.

CVSS3: 4.5
3%
Низкий
около 1 года назад
msrc логотип
CVSS3: 4.5
3%
Низкий
около 1 года назад
debian логотип
CVE-2024-27281

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in ...

CVSS3: 4.5
3%
Низкий
около 1 года назад
fstec логотип
BDU:2024-02457

Уязвимость встроенного генератора документации RDoc для языка программирования Ruby, связанная с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 4.5
3%
Низкий
больше 1 года назад
oracle-oval логотип
ELSA-2024-3671

ELSA-2024-3671: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-3670

ELSA-2024-3670: ruby:3.3 security, bug fix, and enhancement update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-3668

ELSA-2024-3668: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-3546

ELSA-2024-3546: ruby:3.1 security, bug fix, and enhancement update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-4499

ELSA-2024-4499: ruby security update (MODERATE)

11 месяцев назад
oracle-oval логотип
ELSA-2024-3838

ELSA-2024-3838: ruby security update (MODERATE)

около 1 года назад
oracle-oval логотип
ELSA-2024-3500

ELSA-2024-3500: ruby:3.0 security update (MODERATE)

около 1 года назад

Уязвимостей на страницу