Vulnerability GHSA-gcqq-w6gr-h9j9

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
8 years ago
October 24, 2017 at 06:33 PM UTC
Directory traversal vulnerability in RubyZip
0.5.7 - 1.2.0
0.5.7 - 1.2.0

Summary

Directory traversal vulnerability in RubyZip

Details

The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses ../ pathname substrings to write arbitrary files to the filesystem.

Impacted packages

Timeline

Published
8 years ago
October 24, 2017 at 06:33 PM UTC
Fixed (1.2.1)
9 years ago
February 08, 2017 at 11:50 AM UTC
Last Modified
2 years ago
February 16, 2024 at 08:12 AM UTC