Vulnerability Description
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rubygems | Rubygems | <= 2.2.9 |
Related Weaknesses (CWE)
References
- http://blog.rubygems.org/2018/02/15/2.7.6-released.htmlVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
- https://access.redhat.com/errata/RHSA-2018:3729
- https://access.redhat.com/errata/RHSA-2018:3730
- https://access.redhat.com/errata/RHSA-2018:3731
- https://access.redhat.com/errata/RHSA-2019:2028
- https://access.redhat.com/errata/RHSA-2020:0542
- https://access.redhat.com/errata/RHSA-2020:0591
- https://access.redhat.com/errata/RHSA-2020:0663
- https://github.com/rubygems/rubygems/commit/666ef793cad42eed96f7aee1cdf77865db92PatchThird Party Advisory
- https://github.com/rubygems/rubygems/commit/f83f911e19e27cbac1ccce7471d96642241dPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html
- https://usn.ubuntu.com/3621-1/
- https://www.debian.org/security/2018/dsa-4219
- https://www.debian.org/security/2018/dsa-4259
FAQ
What is CVE-2018-1000079?
CVE-2018-1000079 is a vulnerability with a CVSS score of 5.5 (MEDIUM). RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains ...
How severe is CVE-2018-1000079?
CVE-2018-1000079 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1000079?
Check the references section above for vendor advisories and patch information. Affected products include: Rubygems Rubygems.