Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade rubyzip gem (waiting for axlsx) #180

Closed
panterch opened this issue Jun 15, 2017 · 0 comments
Closed

Upgrade rubyzip gem (waiting for axlsx) #180

panterch opened this issue Jun 15, 2017 · 0 comments
Labels

Comments

@panterch
Copy link
Owner

Waiting for:
randym/axlsx#513 and randym/axlsx#536

The Zip::File component has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.

Affected versions: All versions
Fixed versions: 1.2.1
Identifier: CVE-2017-5946
Solution: Upgrade to latest version
Credit: ecneladis
Source: https://github.com/rubyzip/rubyzip/issues/315
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant