• CVE-2024-27281

发布时间: 2024年4月12日

修改时间: 2024年10月31日

概要

An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0.When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored.When loading the documentation cache, object injection and resultant remote code execution are also possible if there were a crafted cache.

CVSS v3 指标

NVD openEuler
Confidentiality Low
Attack Vector Local
CVSS评分 N/A 4.5
Attack Complexity High
Privileges Required None
Scope Unchanged
Integrity Low
User Interaction Required
Availability Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-2364 ruby security update 2024年4月12日

影响产品

产品 状态
KY3.4-4A ruby Fixed
KY3.4-5A ruby Fixed
KY3.5.1 ruby Fixed
KY3.5.2 ruby Fixed