cbcvebase.
CVE-2021-21289
published 2021-02-02

CVE-2021-21289: Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command…

PriorityP348high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
3.51%
88.0th percentile
Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands to be injected using several classes' methods which implicitly use Ruby's Kernel.open method. Exploitation is possible only if untrusted input is used as a local filename and passed to any of these calls: Mechanize::CookieJar#load, Mechanize::CookieJar#save_as, Mechanize#download, Mechanize::Download#save, Mechanize::File#save, and Mechanize::FileResponse#read_body. This is fixed in version 2.7.7.

Affected

7 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianruby-mechanize< ruby-mechanize 2.7.7-1 (bookworm)ruby-mechanize 2.7.7-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
mechanize_projectmechanize>= 2.0 < 2.7.72.7.7
mechanize_projectmechanize>= 2.0.0 < 2.7.72.7.7
sparklemotionmechanize

CVSS provenance

nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv8.3HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.