Description
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.
Remediation
References
Related Vulnerabilities
WordPress Plugin Page Builder:Live Composer Cross-Site Scripting (1.5.22)
WordPress 3.0.4 Multiple Vulnerabilities (0.6.2 - 3.0.4)
XWiki Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-32732)
Oracle Database Server CVE-2007-5520 Vulnerability (CVE-2007-5520)
WordPress Plugin Admin Pack by SITE CASEIRO Cross-Site Scripting (1.1)