Ruby-Lang Rdoc vulnerabilities
3 known vulnerabilities affecting ruby-lang/rdoc.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2024-27281LOW≥ 6.3.3, < 6.3.4.1≥ 6.4.0, < 6.4.1.1+2 more2024-03-25
CVE-2024-27281 [LOW] CWE-502 RDoc RCE vulnerability with .rdoc_options
RDoc RCE vulnerability with .rdoc_options
An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0.
When parsing `.rdoc_options` (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the classes that can be restored.
When loading the documentation cache, object injection and resultant remot
ghsaosv
CVE-2021-31799HIGHCVSS 7.0≥ 3.11, < 6.3.12021-07-30
CVE-2021-31799 [HIGH] CWE-78 CVE-2021-31799: In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to exe
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
ghsanvdosv
CVE-2013-0256MEDIUMCVSS 4.3≥ 2.3.0, < 3.12v4.0.02013-03-01
CVE-2013-0256 [MEDIUM] CWE-79 CVE-2013-0256: darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not pr
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
ghsanvdosv