HIGH7.0
GHSA-ggxm-pgc9-g7fp
Arbitrary Code Execution in Rdoc
Quick fix
GHSA-ggxm-pgc9-g7fp — rdoc: upgrade to the fixed version with the command below.
bundle update rdocDetails
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-31799[ADVISORY]
- https://github.com/ruby/rdoc/commit/a7f5d6ab88632b3b482fe10611382ff73d14eed7[WEB]
- https://github.com/ruby/rdoc[PACKAGE]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rdoc/CVE-2021-31799.yml[WEB]
- https://lists.debian.org/debian-lts-announce/2021/10/msg00009.html[WEB]
- https://security-tracker.debian.org/tracker/CVE-2021-31799[WEB]
- https://security.gentoo.org/glsa/202401-05[WEB]
- https://security.netapp.com/advisory/ntap-20210902-0004[WEB]
- https://www.oracle.com/security-alerts/cpuapr2022.html[WEB]
- https://www.ruby-lang.org/en/news/2021/05/02/os-command-injection-in-rdoc[WEB]