CVE-2018-6914
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.2%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 10.16% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ruby-lang/ruby · canonical/ubuntu linux · debian/debian linux · redhat/enterprise linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
- http://www.securityfocus.com/bid/103686Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042004Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3729Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3730Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3731Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2028
- https://lists.debian.org/debian-lts-announce/2018/04/msg00023.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00024.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3626-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4259Third Party Advisory
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-2-10-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-3-7-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-4-4-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-5-1-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/unintentional-file-and-directory-creation-with-directory-traversal-cve-2018-6914/Vendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
- http://www.securityfocus.com/bid/103686Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042004Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3729Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3730Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3731Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2028
- https://lists.debian.org/debian-lts-announce/2018/04/msg00023.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00024.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3626-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4259Third Party Advisory
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-2-10-released/Patch, Release Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.