peter bassill · operator
$ cve CVE-2017-17405 JSON

CVE-2017-17405 EXPLOIT

8.8
HIGH · CVSS 3.0 · EPSS 73.8% (pctl 99)

Patch early

A public exploit exists.

Description

Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe character, the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution.

Scoring

CVSS8.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS73.83% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2017-12-15
Last modified2026-06-17

Affected (8)

VendorProduct
debiandebian linux
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
ruby-langruby

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD