Sha256: 8e6b60324cb0bc0875c1a9e8f79b26c8e8cdb0e23c0be80167b0923ad3c8b211

Contents?: true

Size: 589 Bytes

Versions: 1

Compression:

Stored size: 589 Bytes

Contents

---
gem: ruby_parser-legacy
cve: 2019-18409
date: 2019-10-24
url: https://github.com/zenspider/ruby_parser-legacy/issues/1
title: ruby_parser-legacy world writable files allow local privilege escalation

description: |
  The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local
  privilege escalation because of world-writable files. For example,
  if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used,
  a local user can insert malicious code into the
  ruby_parser-legacy-1.0.0/lib/ruby_parser/legacy/ruby_parser.rb file.

cvss_v2: 4.6
cvss_v3: 7.8

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/ruby_parser-legacy/CVE-2019-18409.yml