ZeroHour

CVE-2017-0903

CVSS 3.0
9.8 critical
EPSS
16%p97
Published
()
Modified
Description

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.

Vendors
rubygemsdebiancanonicalredhat
Products
rubygems, debian linux, ubuntu linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-502
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.