The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
References
Link | Resource |
---|---|
https://rubygems.org/gems/netaddr/versions | Product |
https://github.com/dspinhirne/netaddr-rb/commit/3aac46c00a36e71905eaa619cb94d45bff6e3b51 | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-10-09 09:15
Updated : 2022-07-19 10:14
NVD link : CVE-2019-17383
Mitre link : CVE-2019-17383
JSON object : View
CWE
CWE-276
Incorrect Default Permissions
Products Affected
netaddr_project
- netaddr