Ruby 3.0.1 Update Addressing Vulnerabilities

Corrective releases for the Ruby programming language 3.0.1, 2.7.3, 2.6.7, and 2.5.9 have been released, fixing two vulnerabilities:

  • CVE-2021-28965 — a vulnerability in the built-in REXML module that may lead to the creation of an incorrect XML document when parsing and serializing specially crafted XML documents, with its structure not matching the original. The risk posed by this vulnerability heavily depends on the context, but attack scenarios targeting some applications using REXML cannot be ruled out.
  • CVE-2021-28966 — a platform-specific vulnerability for Windows that allows creation of arbitrary directories or files in filesystem locations where write access is permitted for the user under whose rights the Ruby process runs. This issue arises from improper handling of prefixes in the Dir.mktmpdir method, where constructs like “..\\“ are not excluded. For an attack, the process must use external data when constructing the prefix value.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster