CVE-2015-3649

The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a crafted UID, and putting Ruby code in said directory once a meta file is created.
Configurations

Configuration 1 (hide)

cpe:2.3:a:open-uri-cached_project:open-uri-cached:0.0.5:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-08-18 16:29

Updated : 2024-02-04 19:29


NVD link : CVE-2015-3649

Mitre link : CVE-2015-3649

CVE.ORG link : CVE-2015-3649


JSON object : View

Products Affected

open-uri-cached_project

  • open-uri-cached
CWE
CWE-20

Improper Input Validation