Vulnerability GHSA-gcqq-w6gr-h9j9
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
8 years ago
October 24, 2017 at 06:33 PM UTC
Directory traversal vulnerability in RubyZip
0.5.7 - 1.2.0
0.5.7 - 1.2.0
Summary
Directory traversal vulnerability in RubyZip
Details
The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses ../ pathname substrings to write arbitrary files to the filesystem.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
24 days ago
rubyzip path traversal vulnerability
0.5.7 - 3.3.1 GHSA-47m2-wp7j-p9vc
0.5.7 - 3.3.1 GHSA-47m2-wp7j-p9vc
Medium Risk
6 years ago
Rubyzip denial of service
0.5.7 - 1.2.4 GHSA-5m2v-hc64-56h6
0.5.7 - 1.2.4 GHSA-5m2v-hc64-56h6
Critical
8 years ago
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
0.5.7 - 1.2.1 GHSA-vqcq-mrmw-mcmg
0.5.7 - 1.2.1 GHSA-vqcq-mrmw-mcmg
Impacted packages
Timeline
Published
8 years ago
October 24, 2017 at 06:33 PM UTC
Fixed (1.2.1)
9 years ago
February 08, 2017 at 11:50 AM UTC
Last Modified
2 years ago
February 16, 2024 at 08:12 AM UTC