Lucene search

K
cloudfoundryCloud FoundryCFOUNDRY:1269D3F2131B2758F6111555E51EA48A
HistoryApr 12, 2019 - 12:00 a.m.

USN-3945-1: Ruby vulnerabilities | Cloud Foundry

2019-04-1200:00:00
Cloud Foundry
www.cloudfoundry.org
138

0.006 Low

EPSS

Percentile

78.7%

Severity

Medium

Vendor

Canonical Ubuntu

Versions Affected

  • Canonical Ubuntu 18.04

Description

It was discovered that Ruby incorrectly handled certain RubyGems. An attacker could possibly use this issue to execute arbitrary commands. (CVE-2019-8320)

It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-8321, CVE-2019-8322, CVE-2019-8323, CVE-2019-8324, CVE-2019-8325)

CVEs contained in this USN include: CVE-2019-8320, CVE-2019-8321, CVE-2019-8322, CVE-2019-8323, CVE-2019-8324, CVE-2019-8325

Affected Cloud Foundry Products and Versions

Severity is medium unless otherwise noted.

  • All versions of Cloud Foundry cflinuxfs3 prior to 0.80.0

Mitigation

Users of affected products are strongly encouraged to follow one of the mitigations below:

  • The Cloud Foundry project recommends that Cloud Foundry deployments run with cflinuxfs3 version 0.80.0 or later.

References