CVE-2021-28966 PUBLISHED

In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.

EPSS 0.35% · 57.1th percentile

Risk Scores

EPSS Score
0.35%
57.1th percentile

Affected Products

VendorProductVersions
Bitnamiruby-min0, 3.0.0
Bitnamiruby3.0.0, 0, 3.0.0
Bitnamiruby-min0, 3.0.0, 3.0.0
Bitnamiruby0, 3.0.0

Timeline

References

Open in Interactive Console →