CVE-2014-9489
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the -O or --open-files-in-pager flags.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.29% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- gollum project/gollum · gollum project/gollum-lib · gollum project/grit adapter
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2015/01/03/19Issue Tracking, Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/71499Third Party Advisory, VDB Entry
- https://github.com/gollum/gollum/issues/913Issue Tracking, Third Party Advisory
- https://github.com/gollum/grit_adapter/commit/4520d973c81fecfebbeacd2ef2f1849d763951c7Issue Tracking, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2015/01/03/19Issue Tracking, Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/71499Third Party Advisory, VDB Entry
- https://github.com/gollum/gollum/issues/913Issue Tracking, Third Party Advisory
- https://github.com/gollum/grit_adapter/commit/4520d973c81fecfebbeacd2ef2f1849d763951c7Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.