PT-2019-4670 · Ruby+7 · Ruby+7

Publicado

2019-10-01

·

Atualizado

2021-10-19

·

CVE-2019-15845

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ruby versions prior to 2.4.8 Ruby versions 2.5.x through 2.5.6 Ruby versions 2.6.x through 2.6.4
Description The issue arises from the mishandling of path checking within the File.fnmatch functions in Ruby. This could potentially allow a remote attacker to gain unauthorized access to protected information by exploiting the vulnerability with a specially crafted script.
Recommendations For Ruby versions prior to 2.4.8, update to version 2.4.8 or later. For Ruby versions 2.5.x through 2.5.6, update to version 2.5.7 or later. For Ruby versions 2.6.x through 2.6.4, update to version 2.6.5 or later.

Exploit

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2021:2587
ALSA-2021:2588
ALT-PU-2020-1679
ALT-PU-2020-3411
ALT-PU-2021-3068
BDU:2020-00863
CESA-2021_2587
CESA-2021_2588
CVE-2019-15845
DLA-2007-1
DSA-4586-1
DSA-4587-1
MGASA-2019-0408
OPENSUSE-SU-2020:0395-1
OPENSUSE-SU-2020_0395-1
RHSA-2021:2104
RHSA-2021:2230
RHSA-2021:2587
RHSA-2021:2588
RHSA-2021_2587
RHSA-2021_2588
RHSA-2022:0581
RHSA-2022:0582
RLSA-2021:2587
RLSA-2021:2588
SUSE-SU-2020:0737-1
SUSE-SU-2020:1570-1
SUSE-SU-2020_1570-1
USN-4201-1

Produtos afetados

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Ruby
Suse
Ubuntu