Record summary

CVE-2017-0903 has a selected CVSS score of 9.8 (critical).

Description

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.

Description source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListVersions >= 2.0.0affected
GitHub Advisory2.0.0 to < 2.6.14 · Fixed in 2.6.14affected

References

Showing 12 of 16