VDB
ALPINE-CVE-2018-6914
ALPINE-CVE-2018-6914
PUBLISHED
CVSS 7.5 HIGH
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.
Risk Scores
CVSS v3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.23 | ruby | 0, 0, 0 |
| Alpine:v3.8 | ruby | 1.9.3_p286-r0, 0, 1.8.7 |
| Alpine:v3.20 | ruby | 0, 0, 0 |
| Alpine:v3.12 | ruby | 1.8.7, 1.8.7, 1.8.7 |
| Alpine:v3.15 | ruby | 1.9.3_p286-r0, 2.5.0-r0, 2.4.3-r0 |
| Alpine:v3.16 | ruby | 2.5.0-r1, 2.5.0-r0, 2.4.3-r0 |
| Alpine:v3.14 | ruby | 2.0.0_p0-r1, 0, 1.8.7 |
| Alpine:v3.22 | ruby | 0, 0, 0 |
| Alpine:v3.17 | ruby | 2.4.1-r3, 2.4.1-r4, 2.4.1-r5 |
| Alpine:v3.7 | ruby | 1.9.3_p362-r0, 2.4.3-r0, 2.4.2-r1 |
| Alpine:v3.19 | ruby | 1.8.7_p160-r2, 2.5.0-r1, 2.5.0-r0 |
| Alpine:v3.18 | ruby | 1.8.7, 1.8.7, 1.8.7 |
| Alpine:v3.11 | ruby | 1.8.7_p174-r3, 2.0.0, 2.0.0 |
| Alpine:v3.5 | ruby | 2.1.5-r0, 2.3.6-r0, 2.3.5-r0 |
| Alpine:v3.10 | ruby | 2.3.3-r1, 2.5.0-r1, 2.5.0-r0 |
| Alpine:v3.4 | ruby | 2.0.0_p195-r0, 2.3.6-r0, 2.3.5-r0 |
| Alpine:v3.21 | ruby | 0, 0, 0 |
| Alpine:v3.6 | ruby | 2.0.0_p353-r0, 2.0.0_p247-r3, 2.0.0_p247-r2 |
| Alpine:v3.13 | ruby | 1.8.7, 2.4.1-r3, 2.4.1-r4 |
| Alpine:v3.9 | ruby | 2.5.0-r1, 0, 1.8.7 |
Timeline
- Apr 3, 2018 CVE Published
- Dec 3, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch