Lucene search

K
cvelistHackeroneCVELIST:CVE-2017-0903
HistoryOct 10, 2017 - 12:00 a.m.

CVE-2017-0903

2017-10-1000:00:00
CWE-502
hackerone
www.cve.org

9.2 High

AI Score

Confidence

High

0.135 Low

EPSS

Percentile

95.7%

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution.

CNA Affected

[
  {
    "product": "RubyGems",
    "vendor": "HackerOne",
    "versions": [
      {
        "status": "affected",
        "version": "Versions >= 2.0.0"
      }
    ]
  }
]