VDB

ALPINE-CVE-2018-6914

ALPINE-CVE-2018-6914 PUBLISHED CVSS 7.5 HIGH

Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.

Risk Scores

CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.23ruby0, 0, 0
Alpine:v3.8ruby2.3.3-r2, 2.3.3-r1, 2.3.3-r0
Alpine:v3.20ruby0, 2.2.0, 0
Alpine:v3.12ruby1.8.7_p72-r1, 0, 2.2.0
Alpine:v3.15ruby1.9.3_p286-r2, 2.4.1-r3, 2.4.1-r4
Alpine:v3.16ruby1.8.7, 1.8.7, 1.8.7
Alpine:v3.14ruby2.0.0_p195-r0, 0, 1.8.7
Alpine:v3.22ruby0, 0, 0
Alpine:v3.17ruby2.4.1-r4, 2.4.1-r5, 2.4.2-r0
Alpine:v3.7ruby1.9.3_p327-r0, 0, 2.4.3-r0
Alpine:v3.19ruby1.8.7_p160-r3, 0, 2.2.0
Alpine:v3.24ruby2.2.0, 0
Alpine:v3.18ruby1.8.7, 1.8.7, 1.8.7
Alpine:v3.11ruby1.8.7_p174-r3, 2.0.0, 2.0.0
Alpine:v3.5ruby2.2.2-r1, 2.2.0, 0
Alpine:v3.10ruby2.3.3-r0, 0, 2.5.0-r1
Alpine:v3.4ruby2.0.0_p247-r3, 2.2.0, 0
Alpine:v3.21ruby2.2.0, 0, 0
Alpine:v3.6ruby2.0.0_p247-r2, 2.0.0_p247-r0, 2.0.0_p195-r0

…and 3 more

Timeline

  • Apr 3, 2018 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›