VDB
Sign up
MEDIUM5.5

GHSA-x4vj-279x-qwf2

VladTheEnterprising allows local users to write to arbitrary files via a symlink attack

Details

`lib/vlad/dba/mysql.rb` in the VladTheEnterprising gem 0.2 for Ruby allows local users to write to arbitrary files via a symlink attack on `/tmp/my.cnf.#{target_host}`.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/VladTheEnterprising
Introduced in: 0

No fixed version published yet for VladTheEnterprising (bundler). Pin to a known-safe version or switch to an alternative.

References