Description
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1358-1 | ruby1.9.1 security update |
Debian DLA |
DLA-1359-1 | ruby1.8 security update |
Debian DLA |
DLA-1421-1 | ruby2.1 security update |
Debian DSA |
DSA-4259-1 | ruby2.3 security update |
EUVD |
EUVD-2018-20389 | In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the Dir.open, Dir.new, Dir.entries and Dir.empty? methods do not check NULL characters. When using the corresponding method, unintentional directory traversal may be performed. |
Ubuntu USN |
USN-3626-1 | Ruby vulnerabilities |
References
History
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T07:02:26.043Z
Reserved: 2018-03-19T00:00:00.000Z
Link: CVE-2018-8780
No data.
Status : Modified
Published: 2018-04-03T22:29:00.947
Modified: 2024-11-21T04:14:17.963
Link: CVE-2018-8780
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN