The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
References
Link | Resource |
---|---|
https://github.com/dspinhirne/netaddr-rb/commit/3aac46c00a36e71905eaa619cb94d45bff6e3b51 | Patch Third Party Advisory |
https://rubygems.org/gems/netaddr/versions | Product |
https://github.com/dspinhirne/netaddr-rb/commit/3aac46c00a36e71905eaa619cb94d45bff6e3b51 | Patch Third Party Advisory |
https://rubygems.org/gems/netaddr/versions | Product |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:32
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/dspinhirne/netaddr-rb/commit/3aac46c00a36e71905eaa619cb94d45bff6e3b51 - Patch, Third Party Advisory | |
References | () https://rubygems.org/gems/netaddr/versions - Product |
Information
Published : 2019-10-09 16:15
Updated : 2024-11-21 04:32
NVD link : CVE-2019-17383
Mitre link : CVE-2019-17383
CVE.ORG link : CVE-2019-17383
JSON object : View
Products Affected
netaddr_project
- netaddr
CWE
CWE-276
Incorrect Default Permissions