A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.
CVSS Details
- CVSS 3.1 Base Score: 7.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ruby | Jun 6, 2019 | Jun 6, 2019 |
| Amazon_linux | — | Upgrade ruby24Upgrade ruby20Upgrade ruby21 | Aug 13, 2019 | Mar 5, 2019 |
| Debian | — | Upgrade rubygemsUpgrade jruby | Apr 1, 2019 | Apr 1, 2019 |
| Freebsd | — | Upgrade ruby25-gemsUpgrade ruby24-gemsUpgrade ruby23-gems | Mar 16, 2019 | Mar 15, 2019 |
| Oracle Solaris | — | Upgrade runtime/ruby-25 to version 2.5.3-11.4.11.0.1.3.0 on Solaris 11.4Upgrade runtime/ruby-26 to version 2.6.0-11.4.11.0.1.3.0 on Solaris 11.4Upgrade runtime/ruby-21 to version 2.1.6-11.4.11.0.1.3.0 on Solaris 11.4Upgrade runtime/ruby-21/ruby-tk to version 2.1.6-11.4.11.0.1.3.0 on Solaris 11.4Upgrade runtime/ruby-23/ruby-tk to version 2.3.8-11.4.11.0.1.3.0 on Solaris 11.4Upgrade runtime/ruby-23 to version 2.3.8-11.4.11.0.1.3.0 on Solaris 11.4 | Jul 17, 2019 | Jun 6, 2019 |
| Suse | — | Upgrade ruby2.5-develUpgrade ruby2.5-docUpgrade ruby2.5Upgrade libruby2_5-2_5Upgrade ruby2.1-stdlibUpgrade ruby2.5-devel-extraUpgrade ruby2.5-stdlibUpgrade ruby-bundled-gems-rpmhelperUpgrade ruby2.1-develUpgrade ruby2.5-doc-riUpgrade libruby2_1-2_1Upgrade ruby2.1Upgrade yast2-ruby-bindings | Jul 22, 2019 | Mar 5, 2019 |
| Ubuntu | — | Upgrade libruby1.9.1Upgrade ruby2.5Upgrade ruby1.9.1Upgrade libruby2.5Upgrade libruby2.3Upgrade libruby2.0Upgrade ruby2.3Upgrade ruby2.0Upgrade ruby1.9.3 | Apr 24, 2019 | Mar 5, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub