cbcvebase.
CVE-2017-0903
published 2017-10-11

CVE-2017-0903: RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.

Affected

88 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianrubygems< rubygems 3.2.0~rc.1-1 (bookworm)rubygems 3.2.0~rc.1-1 (bookworm)
hackeronerubygems
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL