VDB

ALPINE-CVE-2018-6914

ALPINE-CVE-2018-6914 PUBLISHED CVSS 7.5 HIGH

Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.

Risk Scores

CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.23ruby0, 0, 0
Alpine:v3.8ruby1.9.3_p286-r0, 0, 1.8.7
Alpine:v3.20ruby0, 0, 0
Alpine:v3.12ruby1.8.7, 1.8.7, 1.8.7
Alpine:v3.15ruby1.9.3_p286-r0, 2.5.0-r0, 2.4.3-r0
Alpine:v3.16ruby2.5.0-r1, 2.5.0-r0, 2.4.3-r0
Alpine:v3.14ruby2.0.0_p0-r1, 0, 1.8.7
Alpine:v3.22ruby0, 0, 0
Alpine:v3.17ruby2.4.1-r3, 2.4.1-r4, 2.4.1-r5
Alpine:v3.7ruby1.9.3_p362-r0, 2.4.3-r0, 2.4.2-r1
Alpine:v3.19ruby1.8.7_p160-r2, 2.5.0-r1, 2.5.0-r0
Alpine:v3.18ruby1.8.7, 1.8.7, 1.8.7
Alpine:v3.11ruby1.8.7_p174-r3, 2.0.0, 2.0.0
Alpine:v3.5ruby2.1.5-r0, 2.3.6-r0, 2.3.5-r0
Alpine:v3.10ruby2.3.3-r1, 2.5.0-r1, 2.5.0-r0
Alpine:v3.4ruby2.0.0_p195-r0, 2.3.6-r0, 2.3.5-r0
Alpine:v3.21ruby0, 0, 0
Alpine:v3.6ruby2.0.0_p353-r0, 2.0.0_p247-r3, 2.0.0_p247-r2
Alpine:v3.13ruby1.8.7, 2.4.1-r3, 2.4.1-r4
Alpine:v3.9ruby2.5.0-r1, 0, 1.8.7

Timeline

  • Apr 3, 2018 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›