blog.rubygems.org
http://blog.rubygems.org/2017/10/09/2.6.14-released.html CVE-2017-0903
CRITICAL
RubyGems vulnerable to Deserialization of Untrusted Data
Record summary
CVE-2017-0903 has a selected CVSS score of 9.8 (critical).
Description
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
RubyGemsBrowse HackerOne / RubyGems | CVE List | Versions >= 2.0.0 | affected |
rubygems-updateBrowse RubyGems / rubygems-update | GitHub Advisory | 2.0.0 to < 2.6.14 · Fixed in 2.6.14 | affected |
References
Showing 12 of 16blog.rubygems.org
http://blog.rubygems.org/2017/10/09/unsafe-object-deserialization-vulnerability.html 101275vdb entry
http://www.securityfocus.com/bid/101275 RHSA-2017:3485Vendor advisory
https://access.redhat.com/errata/RHSA-2017:3485 RHSA-2018:0378Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0378 RHSA-2018:0583Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0583 RHSA-2018:0585Vendor advisory
https://access.redhat.com/errata/RHSA-2018:0585 github.com
https://github.com/rubygems/rubygems github.com
https://github.com/rubygems/rubygems/commit/510b1638ac9bba3ceb7a5d73135dafff9e5bab49 hackerone.com
https://hackerone.com/reports/274990 [debian-lts-announce] 20180714 [SECURITY] [DLA 1421-1] ruby2.1 security updatemailing list
https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-0903