« List of all CVEs

CVE-2021-28966

Published: 7/27/2021 Last updated: 8/3/2024 Reserved: 3/22/2021

In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (1)

conf-ruby

Products affected (1)

Product Vendor Version
n/a n/a < 14.7

References (8)