Description
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
Remediation
References
Related Vulnerabilities
OpenVPN AS Resource Management Errors Vulnerability (CVE-2014-8104)
WordPress Plugin BackUpWordPress Unspecified Vulnerability (3.12)
WordPress Plugin All-in-One Event Calendar Cross-Site Scripting (2.5.18)
Resin Application Server Improper Input Validation Vulnerability (CVE-2012-2965)
WordPress Plugin LearnPress-WordPress LMS Cross-Site Request Forgery (3.2.7.2)