CVE-2017-1000047

CRITICAL

rbenv - Directory Traversal and Arbitrary Code Execution via Ruby Version Specification

Title source: llm
STIX 2.1

Description

rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution

Scores

CVSS v3 9.8
EPSS 0.0371
EPSS Percentile 88.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
rbenv_project/rbenv
Published Jul 17, 2017
Tracked Since Feb 18, 2026