CVE-2019-8321
Description
RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description rubygems: Escape sequence injection vulnerability in verbose CVSS v3: 5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N) Errata / fixed releases ProductPackageAdvisoryReleased CloudForms Management Engine 5.10cfme-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z CloudForms Management Engine 5.10cfme-amazon-smartstate-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z CloudFormsβ¦
Description
rubygems: Escape sequence injection vulnerability in verbose
CVSS v3: 5.3 (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| CloudForms Management Engine 5.10 | cfme-0:5.10.5.1-1.el7cf | RHSA-2019:1429 | 2019-06-11T00:00:00Z |
| CloudForms Management Engine 5.10 | cfme-amazon-smartstate-0:5.10.5.1-1.el7cf | RHSA-2019:1429 | 2019-06-11T00:00:00Z |
| CloudForms Management Engine 5.10 | cfme-appliance-0:5.10.5.1-1.el7cf | RHSA-2019:1429 | 2019-06-11T00:00:00Z |
| CloudForms Management Engine 5.10 | cfme-gemset-0:5.10.5.1-1.el7cf | RHSA-2019:1429 | 2019-06-11T00:00:00Z |
| CloudForms Management Engine 5.10 | ruby-0:2.4.6-91.el7cf | RHSA-2019:1429 | 2019-06-11T00:00:00Z |
| Red Hat Enterprise Linux 7 | ruby-0:2.0.0.648-35.el7_6 | RHSA-2019:1235 | 2019-05-15T00:00:00Z |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | ruby-0:2.0.0.648-37.el7_4 | RHSA-2020:2769 | 2020-06-30T00:00:00Z |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | ruby-0:2.0.0.648-37.el7_4 | RHSA-2020:2769 | 2020-06-30T00:00:00Z |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | ruby-0:2.0.0.648-37.el7_4 | RHSA-2020:2769 | 2020-06-30T00:00:00Z |
| Red Hat Enterprise Linux 8 | ruby:2.5-8010020190711131821.cdc1202b | RHBA-2019:3384 | 2019-11-05T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-ruby24-ruby-0:2.4.6-92.el6 | RHSA-2019:1150 | 2019-05-13T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby25-ruby-0:2.5.5-7.el7 | RHSA-2019:1148 | 2019-05-13T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-ruby24-ruby-0:2.4.6-92.el7 | RHSA-2019:1150 | 2019-05-13T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-ruby25-ruby-0:2.5.5-7.el7 | RHSA-2019:1148 | 2019-05-13T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS | rh-ruby24-ruby-0:2.4.6-92.el7 | RHSA-2019:1150 | 2019-05-13T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-ruby25-ruby-0:2.5.5-7.el7 | RHSA-2019:1148 | 2019-05-13T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | rh-ruby24-ruby-0:2.4.6-92.el7 | RHSA-2019:1150 | 2019-05-13T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-ruby25-ruby-0:2.5.5-7.el7 | RHSA-2019:1148 | 2019-05-13T00:00:00Z |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-ruby24-ruby-0:2.4.6-92.el7 | RHSA-2019:1150 | 2019-05-13T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat Enterprise Linux 6 | rubygems | Not affected |
| Red Hat Software Collections | rh-ruby23-ruby | Fix deferred |
| Red Hat Software Collections | rh-ruby26-ruby | Not affected |
Apply commands
yum update -y cfme
# or:
dnf upgrade -y cfme
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat Enterprise Linux 6 | Not affected |
| redhat | Red Hat Software Collections | Not affected |
OS impact
SUSE Affected 1 release
| Version | Status | Fixed in |
|---|---|---|
| β | Affected | β |
AlmaLinux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | rubygem-abrt-doc-0.3.0-4.module_el8.5.0+2623+08a8ba32.noarch.rpm |
Debian Fixed 5 releases
| Version | Status | Fixed in |
|---|---|---|
| trixie | Fixed | 9.1.17.0-3 |
| sid | Fixed | 9.1.17.0-3 |
| forky | Fixed | 9.1.17.0-3 |
| bullseye | Fixed | 3.2.0~rc.1-1 |
| bookworm | Fixed | 9.1.17.0-3 |
Red Hat Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
Rocky Linux Fixed 1 release
| Version | Status | Fixed in |
|---|---|---|
| 8 | Fixed | β |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| RubyGems | rubygems-update | !< 2.6||<>= 3.0.3 | >= 3.0.3 |
| RubyGems | rubygems-update | >=2.6.0,<2.7.9 | 2.7.9 |
| RubyGems | rubygems-update | >=3.0.0,<3.0.2 | 3.0.2 |
References
- https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html
- https://www.suse.com/security/cve/CVE-2019-8321.html
- https://security-tracker.debian.org/tracker/CVE-2019-8321
- https://errata.rockylinux.org/RLBA-2019:3384
- https://nvd.nist.gov/vuln/detail/CVE-2019-8321
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubygems-update/CVE-2019-8321.yml
- https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
- https://errata.almalinux.org/8/ALBA-2019-3384.html
- https://access.redhat.com/errata/RHBA-2019:3384
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.