rubygem-bundler: Insecure permissions on directory in /tmp/ allows for execution of malicious code
Published Sep 4, 2020
7.8
HIGHCVSS 3.1
EPSS 0.53%
Description
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
Affected products
- Vendor n/a Product Rubygem-Bundler Defaultn/a
- Version bundler versions before 2.1.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Rubygem-Bundler | n/a |
|
No data.
Red Hat Enterprise Linux 8
ruby:2.6-8040020210430142949.522a0ee4
Fixed · RHSA-2021:2588
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-ruby26-ruby-0:2.6.7-119.el7
Fixed · RHSA-2021:2230
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-ruby26-ruby-0:2.6.7-119.el7
Fixed · RHSA-2021:2230
Red Hat 3scale API Management Platform 2
backend
Affected
Red Hat Enterprise Linux 7
rubygem-bundler
Not affected
Red Hat Enterprise Linux 8
ruby:2.5/rubygem-bundler
Will not fix
Red Hat Software Collections
rh-ruby23-rubygem-bundler
Not affected
Red Hat Software Collections
rh-ruby24-rubygem-bundler
Not affected
Red Hat Software Collections
rh-ruby25-rubygem-bundler
Will not fix
Red Hat Software Collections
rh-ruby27-ruby
Not affected
Red Hat Storage 3
rubygem-bundler
Not affected
Red Hat Subscription Asset Manager
ruby193-rubygem-bundler
Not affected
Red Hat Subscription Asset Manager
rubygem-bundler
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | ruby:2.6-8040020210430142949.522a0ee4 | Fixed | RHSA-2021:2588 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby26-ruby-0:2.6.7-119.el7 | Fixed | RHSA-2021:2230 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-ruby26-ruby-0:2.6.7-119.el7 | Fixed | RHSA-2021:2230 |
| Red Hat 3scale API Management Platform 2 | backend | Affected | n/a |
| Red Hat Enterprise Linux 7 | rubygem-bundler | Not affected | n/a |
| Red Hat Enterprise Linux 8 | ruby:2.5/rubygem-bundler | Will not fix | n/a |
| Red Hat Software Collections | rh-ruby23-rubygem-bundler | Not affected | n/a |
| Red Hat Software Collections | rh-ruby24-rubygem-bundler | Not affected | n/a |
| Red Hat Software Collections | rh-ruby25-rubygem-bundler | Will not fix | n/a |
| Red Hat Software Collections | rh-ruby27-ruby | Not affected | n/a |
| Red Hat Storage 3 | rubygem-bundler | Not affected | n/a |
| Red Hat Subscription Asset Manager | ruby193-rubygem-bundler | Not affected | n/a |
| Red Hat Subscription Asset Manager | rubygem-bundler | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The version of rubygem-bundler provided in 'Red Hat Gluster Storage 3' does not contain the vulnerable functionality and is not affected by this vulnerability.
References (8)
- https://access.redhat.com/security/cve/CVE-2019-3881 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1651826 Issue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-g98m-96g9-wfjq Advisory
- https://github.com/rubygems/bundler/issues/6501
- https://github.com/rubygems/bundler/pull/7416/commits/65cfebb041c454c246aaf32a177b0243915a9998
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/bundler/CVE-2019-3881.yml
- https://nvd.nist.gov/vuln/detail/CVE-2019-3881
- https://www.cve.org/CVERecord?id=CVE-2019-3881
Change history (0)
No recorded changes yet.