Remote Code Execution Vulnerability in Ruby on Windows
CVE-2021-28966
7.5HIGH
What is CVE-2021-28966?
A vulnerability in Ruby on Windows allows remote attackers to exploit crafted paths during parameter handling with TmpDir. This can lead to unauthorized code execution, potentially compromising application integrity and security. It is imperative for developers to validate and sanitize user inputs to mitigate this risk. Users are encouraged to apply updates and adhere to security best practices.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved