Search CVE reports


Toggle filters

11 – 20 of 57 results


CVE-2019-8324

Medium priority

Some fixes available 8 of 11

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by...

6 affected packages

jruby, ruby1.9.1, ruby2.0, ruby2.1, ruby2.3, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jruby Not affected Not affected Vulnerable
ruby1.9.1 Not in release Not in release Not in release Not in release
ruby2.0 Not in release Not in release Not in release Not in release
ruby2.1 Not in release Not in release Not in release Not in release
ruby2.3 Not in release Not in release Not in release Not in release
ruby2.5 Not in release Not in release Not in release Fixed
Show less packages

CVE-2019-8323

Medium priority

Some fixes available 8 of 11

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.

6 affected packages

jruby, ruby1.9.1, ruby2.0, ruby2.3, ruby2.1, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jruby Not affected Not affected Vulnerable
ruby1.9.1 Not in release Not in release Not in release Not in release
ruby2.0 Not in release Not in release Not in release Not in release
ruby2.3 Not in release Not in release Not in release Not in release
ruby2.1 Not in release Not in release Not in release Not in release
ruby2.5 Not in release Not in release Not in release Fixed
Show less packages

CVE-2019-8322

Medium priority

Some fixes available 8 of 11

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

6 affected packages

jruby, ruby2.0, ruby2.3, ruby1.9.1, ruby2.1, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jruby Not affected Not affected Vulnerable
ruby2.0 Not in release Not in release Not in release Not in release
ruby2.3 Not in release Not in release Not in release Not in release
ruby1.9.1 Not in release Not in release Not in release Not in release
ruby2.1 Not in release Not in release Not in release Not in release
ruby2.5 Not in release Not in release Not in release Fixed
Show less packages

CVE-2019-8321

Medium priority

Some fixes available 8 of 11

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.

6 affected packages

ruby2.0, jruby, ruby2.1, ruby1.9.1, ruby2.3, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby2.0 Not in release Not in release Not in release Not in release
jruby Not affected Not affected Vulnerable
ruby2.1 Not in release Not in release Not in release Not in release
ruby1.9.1 Not in release Not in release Not in release Not in release
ruby2.3 Not in release Not in release Not in release Not in release
ruby2.5 Not in release Not in release Not in release Fixed
Show less packages

CVE-2019-8320

Medium priority

Some fixes available 7 of 10

A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If...

6 affected packages

jruby, ruby2.1, ruby2.5, ruby1.9.1, ruby2.0, ruby2.3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
jruby Not affected Not affected Vulnerable
ruby2.1 Not in release Not in release Not in release Not in release
ruby2.5 Not in release Not in release Not in release Fixed
ruby1.9.1 Not in release Not in release Not in release Not in release
ruby2.0 Not in release Not in release Not in release Not in release
ruby2.3 Not in release Not in release Not in release Not in release
Show less packages

CVE-2018-8780

Medium priority
Fixed

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method,...

4 affected packages

ruby2.0, ruby1.9.1, ruby2.3, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby2.0 Not in release
ruby1.9.1 Not in release
ruby2.3 Not in release
ruby2.5 Fixed
Show less packages

CVE-2018-8779

Medium priority
Fixed

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.

4 affected packages

ruby1.9.1, ruby2.0, ruby2.3, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby1.9.1 Not in release
ruby2.0 Not in release
ruby2.3 Not in release
ruby2.5 Fixed
Show less packages

CVE-2018-8778

Medium priority
Fixed

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the...

4 affected packages

ruby2.0, ruby1.9.1, ruby2.3, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby2.0 Not in release
ruby1.9.1 Not in release
ruby2.3 Not in release
ruby2.5 Fixed
Show less packages

CVE-2018-8777

Low priority
Fixed

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker can pass a large HTTP request with a crafted header to WEBrick server or a crafted body to WEBrick server/handler...

4 affected packages

ruby1.9.1, ruby2.0, ruby2.3, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby1.9.1 Not in release
ruby2.0 Not in release
ruby2.3 Not in release
ruby2.5 Fixed
Show less packages

CVE-2018-6914

Medium priority
Fixed

Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary...

4 affected packages

ruby1.9.1, ruby2.0, ruby2.3, ruby2.5

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby1.9.1 Not in release
ruby2.0 Not in release
ruby2.3 Not in release
ruby2.5 Fixed
Show less packages