PT-2019-4670 · Ruby+7 · Ruby+7

Published

2019-10-01

·

Updated

2021-10-19

·

CVE-2019-15845

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ruby versions prior to 2.4.8 Ruby versions 2.5.x through 2.5.6 Ruby versions 2.6.x through 2.6.4
Description The issue arises from the mishandling of path checking within the File.fnmatch functions in Ruby. This could potentially allow a remote attacker to gain unauthorized access to protected information by exploiting the vulnerability with a specially crafted script.
Recommendations For Ruby versions prior to 2.4.8, update to version 2.4.8 or later. For Ruby versions 2.5.x through 2.5.6, update to version 2.5.7 or later. For Ruby versions 2.6.x through 2.6.4, update to version 2.6.5 or later.

Exploit

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:2587
ALSA-2021:2588
ALT-PU-2020-1679
ALT-PU-2020-3411
ALT-PU-2021-3068
BDU:2020-00863
CESA-2021_2587
CESA-2021_2588
CVE-2019-15845
DLA-2007-1
DSA-4586-1
DSA-4587-1
MGASA-2019-0408
OPENSUSE-SU-2020:0395-1
OPENSUSE-SU-2020_0395-1
RHSA-2021:2104
RHSA-2021:2230
RHSA-2021:2587
RHSA-2021:2588
RHSA-2021_2587
RHSA-2021_2588
RHSA-2022:0581
RHSA-2022:0582
RLSA-2021:2587
RLSA-2021:2588
SUSE-SU-2020:0737-1
SUSE-SU-2020:1570-1
SUSE-SU-2020_1570-1
USN-4201-1

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Ruby
Suse
Ubuntu