PT-2019-6814 · Ruby · Rubygems Passenger

Kurt Seifried

·

Publicado

2019-11-19

·

Atualizado

2022-04-23

·

CVE-2012-6135

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions RubyGems passenger versions 4.0.0.beta1 through 4.0.0.beta2
Description The issue allows remote attackers to delete arbitrary files during the startup process. It affects both open source and Enterprise versions.
Recommendations For versions 4.0.0.beta1 and 4.0.0.beta2, consider restricting access to sensitive files during the startup process until a patch is available. As a temporary workaround, consider disabling the startup process temporarily to prevent exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-6135
GHSA-8MW8-J583-VQFG

Produtos afetados

Rubygems Passenger