RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2017-10-10T00:00:00

Updated: 2018-07-14T09:57:01

Reserved: 2016-11-30T00:00:00


Link: CVE-2017-0903

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2017-10-11T18:29:00.583

Modified: 2019-10-09T23:21:10.290


Link: CVE-2017-0903

JSON object: View

cve-icon Redhat Information

No data.

CWE