RubyGems passenger gem allows remote attackers to delete files
High severity
GitHub Reviewed
Published
Apr 23, 2022
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Description
Published by the National Vulnerability Database
Nov 19, 2019
Published to the GitHub Advisory Database
Apr 23, 2022
Reviewed
Mar 20, 2023
Last updated
Jul 5, 2023
RubyGems passenger 4.0.0 betas 1 and 2 allows remote attackers to delete arbitrary files during the startup process.
Affects both open source and Enterprise versions (4.0.0.beta1, 4.0.0.beta2).
References