Description
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
Remediation
References
Related Vulnerabilities
Microsoft SQL Server CVE-2023-36420 Vulnerability (CVE-2023-36420)
Apache Tomcat Other Vulnerability (CVE-2002-0935)
WordPress Plugin Poll, Survey, Questionnaire and Voting system SQL Injection (1.5.2)
Oracle JRE CVE-2013-5805 Vulnerability (CVE-2013-5805)
WordPress Plugin JiangQie Official Website Mini Program SQL Injection (1.1.0)