Description
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
Remediation
References
Related Vulnerabilities
Atlassian Jira CVE-2019-20403 Vulnerability (CVE-2019-20403)
WordPress Plugin JobSearch WP Job Board Cross-Site Scripting (1.5.4)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-3093)
Oracle Database Server CVE-2009-0997 Vulnerability (CVE-2009-0997)
WordPress Plugin Html5 Audio Player-Audio Player for WordPress Cross-Site Scripting (2.1.2)