ALPINE-CVE-2018-8780 PUBLISHED CVSS 9.100000381469727 CRITICAL

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.

Risk Scores

CVSS v3.0
9.100000381469727
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.12ruby0, 2.5.0-r1, 2.5.0-r0
Alpine:v3.16ruby2.4.1-r1, 2.5.0-r1, 2.5.0-r0
Alpine:v3.18ruby0, 2.5.0-r1, 2.5.0-r0
Alpine:v3.9ruby1.8.7, 0, 2.5.0-r1
Alpine:v3.15ruby0, 2.5.0-r1, 2.5.0-r0
Alpine:v3.13ruby2.5.0-r1, 0, 1.8.7
Alpine:v3.7ruby2.4.3-r0, 2.4.2-r1, 2.4.2-r0
Alpine:v3.11ruby2.0.0, 2.0.0, 1.9.3
Alpine:v3.20ruby0, 0, 0
Alpine:v3.22ruby0, 0, 0
Alpine:v3.17ruby2.0.0_p481-r0, 0, 1.8.7
Alpine:v3.8ruby2.5.0-r1, 2.0.0, 2.1.5-r0
Alpine:v3.6ruby2.2.3-r1, 2.3.1-r0, 2.3.1-r1
Alpine:v3.19ruby2.4.2-r0, 2.5.0-r1, 2.5.0-r0
Alpine:v3.14ruby2.2.2-r1, 2.5.0-r1, 2.5.0-r0
Alpine:v3.4ruby2.3.6-r0, 2.3.5-r0, 2.3.1-r0
Alpine:v3.23ruby0, 0, 0
Alpine:v3.5ruby2.2.1-r0, 2.1.5-r1, 2.1.5-r0
Alpine:v3.21ruby0, 0, 0
Alpine:v3.10ruby2.3.2-r0, 2.2.2-r1, 2.4.0-r3

Timeline

References

Open in Interactive Console →