Lucene search

K
osvGoogleOSV:USN-5020-1
HistoryJul 21, 2021 - 2:20 p.m.

ruby2.3, ruby2.5, ruby2.7 vulnerabilities

2021-07-2114:20:02
Google
osv.dev
13
ruby
vulnerabilities
arbitrary code execution
port scans
service banner extractions
tls bypass

AI Score

7.8

Confidence

Low

EPSS

0.01

Percentile

83.7%

It was discovered that Ruby incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2021-31799)

It was discovered that Ruby incorrectly handled certain inputs.
An attacker could possibly use this issue to conduct
port scans and service banner extractions. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-31810)

It was discovered that Ruby incorrectly handled certain inputs.
An attacker could possibly use this issue to perform
machine-in-the-middle attackers to bypass the TLS protection.
(CVE-2021-32066)