cbcvebase.
CVE-2017-0903
published 2017-10-11

CVE-2017-0903: RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can…

PriorityP266critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
15.85%
96.5th percentile
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.

Affected

88 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianrubygems< rubygems 3.2.0~rc.1-1 (bookworm)rubygems 3.2.0~rc.1-1 (bookworm)
hackeronerubygems
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems
rubygemsrubygems

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/rubygems/rubygems/commit/510b1638ac9bba3ceb7a5d73135dafff9e5bab49
  • Monitor for YAML deserialization of gem specifications that instantiates classes outside of expected whitelisted types — this is the bypass mechanism for CVE-2017-0903.
  • Alert on processes inspecting or parsing .gem files (e.g., via `gem inspect` or server-side gem processing) running RubyGems 2.0.0–2.6.13, as unsafe YAML deserialization can trigger arbitrary code execution in the Ruby interpreter context.
  • Server-side gem processing applications are the primary attack surface; client-only rubygems usage is not impacted.
  • ·Vulnerable RubyGems version range is 2.0.0 through 2.6.13; version 2.6.14 contains the fix.
  • ·Red Hat Enterprise Linux 6 ships an unaffected version of rubygems; RHEL 7 and rh-ruby22/rh-ruby23 in Red Hat Software Collections are affected.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.