CVE-2018-8780
—CVSS 3.0
9.1 critical
EPSS
10%p95
Published
()
Modified
Description
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
In the news0 stories
No ingested article mentions this CVE yet.