Ruby CVE-2017-17405 Multiple Command Execution Vulnerabilities
BID:102204
Info
Ruby CVE-2017-17405 Multiple Command Execution Vulnerabilities
| Bugtraq ID: | 102204 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-17405 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2017 12:00AM |
| Updated: | Dec 19 2017 09:01PM |
| Credit: | Etienne Stalmans from the Heroku product security team. |
| Vulnerable: |
Ruby-Lang Ruby 2.4.2 Ruby-Lang Ruby 2.4.1 Ruby-Lang Ruby 2.3.5 Ruby-Lang Ruby 2.3.4 Ruby-Lang Ruby 2.3 Ruby-Lang Ruby 2.2.8 Ruby-Lang Ruby 2.2.7 Ruby-Lang Ruby 2.4.0 Ruby-Lang Ruby 2.2.2 Redhat Subscription Asset Manager 1.0.0 |
| Not Vulnerable: |
Ruby-Lang Ruby 2.4.3 Ruby-Lang Ruby 2.3.6 Ruby-Lang Ruby 2.2.9 |
Discussion
Ruby CVE-2017-17405 Multiple Command Execution Vulnerabilities
Ruby is prone to multiple command-execution vulnerabilities.
An can exploit these issues to execute arbitrary commands within the context of the affected application.
The following versions are affected:
Ruby 2.2.8 and prior
Ruby 2.3.5 and prior
Ruby 2.4.2 and prior
Ruby 2.5.0-preview1 and versions prior to trunk revision r61242
Ruby is prone to multiple command-execution vulnerabilities.
An can exploit these issues to execute arbitrary commands within the context of the affected application.
The following versions are affected:
Ruby 2.2.8 and prior
Ruby 2.3.5 and prior
Ruby 2.4.2 and prior
Ruby 2.5.0-preview1 and versions prior to trunk revision r61242
Exploit / POC
Ruby CVE-2017-17405 Multiple Command Execution Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ruby CVE-2017-17405 Multiple Command Execution Vulnerabilities
References:
References:
- Bug 1526189 - (CVE-2017-17405) CVE-2017-17405 ruby: Command injection vulnerabil (Red Hat)
- CVE-2017-17405 (Red Hat)
- CVE-2017-17405: Command injection vulnerability in Net::FTP (Ruby-lang)
- Ruby 2.2.9 Released (Ruby-lang)
- Ruby 2.3.6 Released (Ruby-lang)
- Ruby 2.4.3 Released (Ruby-lang)
- Ruby Home Page (Yukihiro Matsumoto)