Lucene search

K
redhatcveRedhat.comRH:CVE-2019-3881
HistoryOct 30, 2019 - 9:46 a.m.

CVE-2019-3881

2019-10-3009:46:40
redhat.com
access.redhat.com
8

0.001 Low

EPSS

Percentile

27.3%

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user’s home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.