8.8
CVSSv2

CVE-2019-8320

Published: 06/06/2019 Updated: 16/08/2020
CVSS v2 Base Score: 8.8 | Impact Score: 9.2 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.4 | Impact Score: 5.2 | Exploitability Score: 2.2
VMScore: 783
Vector: AV:N/AC:M/Au:N/C:N/I:C/A:C

Vulnerability Summary

A Directory Traversal issue exists in RubyGems 2.7.6 and later up to and including 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rubygems rubygems

Vendor Advisories

Debian Bug report logs - #925987 CVE-2019-8320 CVE-2019-8321 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 Package: jruby; Maintainer for jruby is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Source for jruby is src:jruby (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debia ...
Synopsis Important: rh-ruby24-ruby security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for rh-ruby24-ruby is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: CloudForms 475 security, bug fix and enhancement update Type/Severity Security Advisory: Important Topic An update is now available for CloudForms Management Engine 510Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scor ...
Synopsis Important: rh-ruby25-ruby security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for rh-ruby25-ruby is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Several vulnerabilities have been discovered in the Rubygems included in the interpreter for the Ruby language, which may result in denial of service or the execution of arbitrary code For the stable distribution (stretch), these problems have been fixed in version 233-1+deb9u6 We recommend that you upgrade your ruby23 packages For the detail ...
An issue was discovered in RubyGems The gem owner command outputs the contents of the API response directly to stdout Therefore, if the response is crafted, escape sequence injection may occur(CVE-2019-8322) An issue was discovered in RubyGems Gem::GemcutterUtilities#with_response may output the API response to stdout as it is Therefore, if th ...