Remote Code Execution Vulnerability in Ruby on Windows
CVE-2021-28966

7.5HIGH

Key Information:

Vendor

Ruby-lang

Status
Vendor
CVE Published:
30 July 2021

What is CVE-2021-28966?

A vulnerability in Ruby on Windows allows remote attackers to exploit crafted paths during parameter handling with TmpDir. This can lead to unauthorized code execution, potentially compromising application integrity and security. It is imperative for developers to validate and sanitize user inputs to mitigate this risk. Users are encouraged to apply updates and adhere to security best practices.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.