Search CVE reports
31 – 40 of 51 results
CVE-2019-8324
Medium prioritySome fixes available 8 of 11
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by...
6 affected packages
jruby, ruby1.9.1, ruby2.0, ruby2.1, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jruby | Not affected | — | Not affected | Vulnerable | Not affected |
ruby1.9.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.0 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.3 | Not in release | Not in release | Not in release | Not in release | Fixed |
ruby2.5 | Not in release | Not in release | Not in release | Fixed | Not in release |
CVE-2019-8323
Medium prioritySome fixes available 8 of 11
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
6 affected packages
jruby, ruby1.9.1, ruby2.0, ruby2.1, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jruby | Not affected | — | Not affected | Vulnerable | Not affected |
ruby1.9.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.0 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.3 | Not in release | Not in release | Not in release | Not in release | Fixed |
ruby2.5 | Not in release | Not in release | Not in release | Fixed | Not in release |
CVE-2019-8322
Medium prioritySome fixes available 8 of 11
An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.
6 affected packages
jruby, ruby1.9.1, ruby2.0, ruby2.1, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jruby | Not affected | — | Not affected | Vulnerable | Not affected |
ruby1.9.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.0 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.3 | Not in release | Not in release | Not in release | Not in release | Fixed |
ruby2.5 | Not in release | Not in release | Not in release | Fixed | Not in release |
CVE-2019-8321
Medium prioritySome fixes available 8 of 11
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
6 affected packages
jruby, ruby1.9.1, ruby2.0, ruby2.1, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jruby | Not affected | — | Not affected | Vulnerable | Not affected |
ruby1.9.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.0 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.3 | Not in release | Not in release | Not in release | Not in release | Fixed |
ruby2.5 | Not in release | Not in release | Not in release | Fixed | Not in release |
CVE-2019-8320
Medium prioritySome fixes available 7 of 11
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If...
6 affected packages
jruby, ruby1.9.1, ruby2.0, ruby2.1, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
jruby | Not affected | — | Not affected | Vulnerable | Not affected |
ruby1.9.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.0 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.3 | Not in release | Not in release | Not in release | Not in release | Fixed |
ruby2.5 | Not in release | Not in release | Not in release | Fixed | Not in release |
CVE-2018-16396
Medium priorityAn issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
4 affected packages
ruby1.9.1, ruby2.0, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby1.9.1 | — | — | — | Not in release | Not in release |
ruby2.0 | — | — | — | Not in release | Not in release |
ruby2.3 | — | — | — | Not in release | Fixed |
ruby2.5 | — | — | — | Fixed | Not in release |
CVE-2018-16395
Medium prioritySome fixes available 7 of 9
An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. When two OpenSSL::X509::Name objects are compared using ==, depending on the ordering,...
5 affected packages
ruby-openssl, ruby1.9.1, ruby2.0, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby-openssl | Not in release | Not in release | Not in release | Needs evaluation | Not in release |
ruby1.9.1 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.0 | Not in release | Not in release | Not in release | Not in release | Not in release |
ruby2.3 | Not in release | Not in release | Not in release | Not in release | Fixed |
ruby2.5 | Not in release | Not in release | Not in release | Fixed | Not in release |
CVE-2018-8780
Medium priorityIn Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method,...
4 affected packages
ruby1.9.1, ruby2.0, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby1.9.1 | — | — | — | Not in release | Not in release |
ruby2.0 | — | — | — | Not in release | Not in release |
ruby2.3 | — | — | — | Not in release | Fixed |
ruby2.5 | — | — | — | Fixed | Not in release |
CVE-2018-8779
Medium priorityIn Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
4 affected packages
ruby1.9.1, ruby2.0, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby1.9.1 | — | — | — | Not in release | Not in release |
ruby2.0 | — | — | — | Not in release | Not in release |
ruby2.3 | — | — | — | Not in release | Fixed |
ruby2.5 | — | — | — | Fixed | Not in release |
CVE-2018-8778
Medium priorityIn Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the...
4 affected packages
ruby1.9.1, ruby2.0, ruby2.3, ruby2.5
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
ruby1.9.1 | — | — | — | Not in release | Not in release |
ruby2.0 | — | — | — | Not in release | Not in release |
ruby2.3 | — | — | — | Not in release | Fixed |
ruby2.5 | — | — | — | Fixed | Not in release |