peter bassill · operator
$ cve CVE-2017-0901 JSON

CVE-2017-0901 EXPLOIT

7.5
HIGH · CVSS 3.0 · EPSS 28.7% (pctl 98)

Patch early

A public exploit exists.

Description

RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.

Scoring

CVSS7.5 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS28.74% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2017-08-31
Last modified2026-06-17

Affected (9)

VendorProduct
canonicalubuntu linux
debiandebian linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
rubygemsrubygems

Public exploits

SourceTitleDate
exploit-dbRubyGems < 2.6.13 - Arbitrary File Overwrite2017-09-04

References

→ the Explorer  ·  watch your stack  ·  NVD