VDB

CVE-2021-28966

CVE-2021-28966 PUBLISHED

In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.

EPSS 0.25% · 48.3th percentile

Risk Scores

EPSS Score
0.25%
48.3th percentile

Affected Products

VendorProductVersions
Bitnamiruby-min3.0.0, 0
Bitnamiruby0, 0, 3.0.0
Bitnamiruby-min0, 0, 3.0.0
Bitnamiruby0, 3.0.0

Timeline

  • CVE Published
  • Apr 7, 2021 PoC Published
  • Jul 28, 2021 EPSS Score
  • Aug 7, 2021 EPSS Score
  • Sep 2, 2021 EPSS Score
  • Nov 23, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Jan 22, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 22, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 19, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›