Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS03bTJ3LTlndzctYzN4cM31tA
open-uri-cached Gem for Ruby Unsafe Temporary File Creation Enables Code Execution
The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a crafted UID, and putting Ruby code in said directory once a metafile is created.
Permalink: https://github.com/advisories/GHSA-7m2w-9gw7-c3xpJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS03bTJ3LTlndzctYzN4cM31tA
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: 10 months ago
CVSS Score: 7.8
CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-7m2w-9gw7-c3xp, CVE-2015-3649
References:
- https://nvd.nist.gov/vuln/detail/CVE-2015-3649
- http://www.benjaminfleischer.com/2013/03/20/yaml-and-security-in-ruby/
- http://www.openwall.com/lists/oss-security/2015/05/06/2
- https://github.com/tigris/open-uri-cached/issues/8
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/open-uri-cached/CVE-2015-3649.yml
- http://seclists.org/oss-sec/2015/q2/373
- https://github.com/tigris/open-uri-cached/blob/master/lib/open-uri/cached.rb
- https://web.archive.org/web/20210119122105/http://www.securityfocus.com/bid/74469
- https://github.com/advisories/GHSA-7m2w-9gw7-c3xp
Blast Radius: 22.0
Affected Packages
rubygems:open-uri-cached
Dependent packages: 19Dependent repositories: 671
Downloads: 1,126,296 total
Affected Version Ranges: <= 1.0.0
No known fixed version
All affected versions: 0.0.1, 0.0.3, 0.0.4, 0.0.5, 1.0.0