High severity vulnerability that affects rubyzip
High severity
GitHub Reviewed
Published
Jul 31, 2018
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Withdrawn
This advisory was withdrawn on Jun 16, 2020
Description
Published to the GitHub Advisory Database
Jul 31, 2018
Reviewed
Jun 16, 2020
Withdrawn
Jun 16, 2020
Last updated
Jan 9, 2023
Withdrawn, accidental duplicate publish.
The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.
References