RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack appear to be exploitable via victim must run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability appears to have been fixed in 2.7.6.
http://blog.rubygems.org/2018/02/15/2.7.6-released.html
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
https://access.redhat.com/errata/RHSA-2018:3729
https://access.redhat.com/errata/RHSA-2018:3730
https://access.redhat.com/errata/RHSA-2018:3731
https://access.redhat.com/errata/RHSA-2019:2028
https://github.com/rubygems/rubygems/commit/254e3d0ee873c008c0b74e8b8abcbdab4caa0a6d
https://lists.debian.org/debian-lts-announce/2018/04/msg00017.html
https://lists.debian.org/debian-lts-announce/2018/08/msg00028.html
https://lists.debian.org/debian-lts-announce/2019/05/msg00028.html
https://usn.ubuntu.com/3621-1/
https://usn.ubuntu.com/3621-2/
https://usn.ubuntu.com/3685-1/
Source: MITRE
Published: 2018-03-13
Updated: 2019-05-20
Type: CWE-502
Base Score: 6.8
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
Impact Score: 6.4
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.8
Severity: HIGH
OR
cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:* versions up to 2.2.9 (inclusive)
OR
cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:* versions up to 2.3.6 (inclusive)
OR
cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:* versions up to 2.4.3 (inclusive)
OR
cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:* versions up to 2.5.0 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
142322 | EulerOS 2.0 SP2 : ruby (EulerOS-SA-2020-2395) | Nessus | Huawei Local Security Checks | medium |
137599 | SUSE SLES12 Security Update : ruby2.1 (SUSE-SU-2020:1570-1) | Nessus | SuSE Local Security Checks | high |
135605 | EulerOS Virtualization 3.0.2.2 : ruby (EulerOS-SA-2020-1443) | Nessus | Huawei Local Security Checks | high |
134484 | EulerOS Virtualization for ARM 64 3.0.2.0 : ruby (EulerOS-SA-2020-1195) | Nessus | Huawei Local Security Checks | high |
134261 | RHEL 7 : ruby (RHSA-2020:0663) | Nessus | Red Hat Local Security Checks | high |
134063 | RHEL 7 : ruby (RHSA-2020:0591) | Nessus | Red Hat Local Security Checks | high |
133785 | RHEL 7 : ruby (RHSA-2020:0542) | Nessus | Red Hat Local Security Checks | high |
132492 | NewStart CGSL CORE 5.05 / MAIN 5.05 : ruby Multiple Vulnerabilities (NS-SA-2019-0245) | Nessus | NewStart CGSL Local Security Checks | high |
131412 | NewStart CGSL CORE 5.04 / MAIN 5.04 : ruby Multiple Vulnerabilities (NS-SA-2019-0221) | Nessus | NewStart CGSL Local Security Checks | high |
130712 | EulerOS 2.0 SP3 : ruby (EulerOS-SA-2019-2250) | Nessus | Huawei Local Security Checks | medium |
130692 | EulerOS 2.0 SP5 : ruby (EulerOS-SA-2019-2230) | Nessus | Huawei Local Security Checks | medium |
128332 | CentOS 7 : ruby (CESA-2019:2028) | Nessus | CentOS Local Security Checks | high |
128290 | Amazon Linux 2 : ruby (ALAS-2019-1276) | Nessus | Amazon Linux Local Security Checks | high |
128260 | Scientific Linux Security Update : ruby on SL7.x x86_64 (20190806) | Nessus | Scientific Linux Local Security Checks | high |
127649 | RHEL 7 : ruby (RHSA-2019:2028) | Nessus | Red Hat Local Security Checks | high |
126904 | openSUSE Security Update : ruby-bundled-gems-rpmhelper / ruby2.5 (openSUSE-2019-1771) | Nessus | SuSE Local Security Checks | high |
126617 | SUSE SLED15 / SLES15 Security Update : ruby-bundled-gems-rpmhelper, ruby2.5 (SUSE-SU-2019:1804-1) | Nessus | SuSE Local Security Checks | high |
125297 | Debian DLA-1796-1 : jruby security update | Nessus | Debian Local Security Checks | high |
112167 | Debian DLA-1480-1 : ruby2.1 security update | Nessus | Debian Local Security Checks | high |
111468 | Debian DSA-4259-1 : ruby2.3 - security update | Nessus | Debian Local Security Checks | high |
110551 | Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : Ruby vulnerabilities (USN-3685-1) | Nessus | Ubuntu Local Security Checks | high |
110418 | Debian DSA-4219-1 : jruby - security update | Nessus | Debian Local Security Checks | high |
109136 | Amazon Linux 2 : ruby (ALAS-2018-983) | Nessus | Amazon Linux Local Security Checks | high |
109091 | Debian DLA-1352-1 : jruby security update | Nessus | Debian Local Security Checks | medium |
109058 | Ubuntu 14.04 LTS : Ruby regression (USN-3621-2) | Nessus | Ubuntu Local Security Checks | high |
108879 | Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities (USN-3621-1) | Nessus | Ubuntu Local Security Checks | high |
108846 | Amazon Linux AMI : ruby20 / ruby22,ruby23,ruby24 (ALAS-2018-983) | Nessus | Amazon Linux Local Security Checks | high |