PT-2025-30903 · Rubygems · Measured
Published
2025-07-15
·
Updated
2025-07-15
CVSS v4.0
4.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U |
Impact
A path traversal vulnerability exists where an attacker with access to manipulate inputs when initializing the
Measured::Cache::Json class would be able to instruct the library to read arbitrary files.Patches
Users should update to the latest version.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Measured