Lucene search

K
f5F5F5:K91125274
HistoryApr 14, 2022 - 12:00 a.m.

K91125274 : RubyGems vulnerability CVE-2017-0903

2022-04-1400:00:00
my.f5.com
35
rubygems
vulnerability
cve-2017-0903
remote code execution
yaml deserialization

AI Score

9.9

Confidence

High

EPSS

0.135

Percentile

95.6%

Security Advisory Description

RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to remote code execution. (CVE-2017-0903)

Impact

There is no impact; F5 products are not affected by this vulnerability.