suse · CVE-2018-8780

Quick triage

Priority: low Published: 2021-05-30 14:11:54 UTC Updated: 2026-04-17 15:29:21 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2018-8780 severity low: SUSE including 301 source package names (2.17-17.3:libruby2_5-2_5-2.5.5-4.3.1, 2.17-17.3:ruby2.5-2.5.5-4.3.1, …), 1008 product×package rows across 251 product lines (Container bci/ruby, Container suse/rmt-server, … (251 product lines)): Fixed 842, Known Affected 157, Known Not Affected 9.

Description:

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.

cvelogic Threat Intelligence