CVE-2019-8321

medium
Published 2019-03-05 Β· Modified 2019-11-05
CVSS v3
β€”
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.5

Description

RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)

Predictions

Exploit likelihood
30%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description rubygems: Escape sequence injection vulnerability in verbose CVSS v3: 5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased CloudForms Management Engine 5.10cfme-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z CloudForms Management Engine 5.10cfme-amazon-smartstate-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z CloudForms…

Description

rubygems: Escape sequence injection vulnerability in verbose

CVSS v3: 5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Errata / fixed releases

ProductPackageAdvisoryReleased
CloudForms Management Engine 5.10cfme-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z
CloudForms Management Engine 5.10cfme-amazon-smartstate-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z
CloudForms Management Engine 5.10cfme-appliance-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z
CloudForms Management Engine 5.10cfme-gemset-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z
CloudForms Management Engine 5.10ruby-0:2.4.6-91.el7cfRHSA-2019:14292019-06-11T00:00:00Z
Red Hat Enterprise Linux 7ruby-0:2.0.0.648-35.el7_6RHSA-2019:12352019-05-15T00:00:00Z
Red Hat Enterprise Linux 7.4 Advanced Update Supportruby-0:2.0.0.648-37.el7_4RHSA-2020:27692020-06-30T00:00:00Z
Red Hat Enterprise Linux 7.4 Telco Extended Update Supportruby-0:2.0.0.648-37.el7_4RHSA-2020:27692020-06-30T00:00:00Z
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutionsruby-0:2.0.0.648-37.el7_4RHSA-2020:27692020-06-30T00:00:00Z
Red Hat Enterprise Linux 8ruby:2.5-8010020190711131821.cdc1202bRHBA-2019:33842019-11-05T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ruby24-ruby-0:2.4.6-92.el6RHSA-2019:11502019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-ruby25-ruby-0:2.5.5-7.el7RHSA-2019:11482019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-ruby24-ruby-0:2.4.6-92.el7RHSA-2019:11502019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSrh-ruby25-ruby-0:2.5.5-7.el7RHSA-2019:11482019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSrh-ruby24-ruby-0:2.4.6-92.el7RHSA-2019:11502019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-ruby25-ruby-0:2.5.5-7.el7RHSA-2019:11482019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-ruby24-ruby-0:2.4.6-92.el7RHSA-2019:11502019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-ruby25-ruby-0:2.5.5-7.el7RHSA-2019:11482019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-ruby24-ruby-0:2.4.6-92.el7RHSA-2019:11502019-05-13T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6rubygemsNot affected
Red Hat Software Collectionsrh-ruby23-rubyFix deferred
Red Hat Software Collectionsrh-ruby26-rubyNot affected

Apply commands

bash fix
Apply RHSA-2019:1429 for CloudForms Management Engine 5.10
yum update -y cfme
# or:
dnf upgrade -y cfme

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Software CollectionsNot affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed rubygem-abrt-doc-0.3.0-4.module_el8.5.0+2623+08a8ba32.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 9.1.17.0-3
sid Fixed 9.1.17.0-3
forky Fixed 9.1.17.0-3
bullseye Fixed 3.2.0~rc.1-1
bookworm Fixed 9.1.17.0-3
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed β€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed β€”

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsrubygems-update!< 2.6||<>= 3.0.3>= 3.0.3
ruby RubyGemsrubygems-update>=2.6.0,<2.7.92.7.9
ruby RubyGemsrubygems-update>=3.0.0,<3.0.23.0.2

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.