CVE-2018-1000079

CVSS v3.0 5.5 (Medium)
55% Progress
CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 1.03 % (84th)
1.03% Progress
Affected Products 1
Advisories 15

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.

Weaknesses
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2018-03-13 15:29:00
(6 years ago)
Updated Date
2018-11-30 11:29:05
(5 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Rubygems 2.2.9 and prior versions cpe:2.3:a:rubygems:rubygems <= 2.2.9

Configuration #2

    CPE23 From Up To
  Rubygems 2.3.6 and prior versions cpe:2.3:a:rubygems:rubygems <= 2.3.6

Configuration #3

    CPE23 From Up To
  Rubygems 2.4.3 and prior versions cpe:2.3:a:rubygems:rubygems <= 2.4.3

Configuration #4

    CPE23 From Up To
  Rubygems 2.5.0 and prior versions cpe:2.3:a:rubygems:rubygems <= 2.5.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...