suse · CVE-2018-1000079

Quick triage

Priority: medium Published: 2021-05-30 14:20:22 UTC Updated: 2026-03-05 06:32:43 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-1000079 severity moderate: SUSE including 307 source package names (2.17-17.3:libruby2_5-2_5-2.5.5-4.3.1, 2.17-17.3:ruby2.5-2.5.5-4.3.1, …), 1029 product×package rows across 259 product lines (Container bci/ruby, Container suse/rmt-server, … (259 product lines)): Fixed 842, Known Affected 157, Known Not Affected 30.

Description:

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.

cvelogic Threat Intelligence