Description
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
Remediation
References
Related Vulnerabilities
Apache HTTP Server CVE-2013-1896 Vulnerability (CVE-2013-1896)
WordPress Plugin bbPress Multiple Vulnerabilities (2.6.4)
MySQL CVE-2018-3283 Vulnerability (CVE-2018-3283)
SharePoint Download of Code Without Integrity Check Vulnerability (CVE-2020-1595)
WordPress Plugin Patreon WordPress Multiple Cross-Site Scripting Vulnerabilities (1.7.1)