Количество 2
Количество 2
CVE-2019-18409
The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used, a local user can insert malicious code into the ruby_parser-legacy-1.0.0/lib/ruby_parser/legacy/ruby_parser.rb file.
GHSA-hhwc-8g49-j8jx
Ruby_parser-legacy Incorrect Permission Assignment for Critical Resource
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2019-18409 The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used, a local user can insert malicious code into the ruby_parser-legacy-1.0.0/lib/ruby_parser/legacy/ruby_parser.rb file. | CVSS3: 7.8 | 0% Низкий | больше 6 лет назад | |
GHSA-hhwc-8g49-j8jx Ruby_parser-legacy Incorrect Permission Assignment for Critical Resource | CVSS3: 7.8 | 0% Низкий | больше 6 лет назад |
Уязвимостей на страницу