CVE-2018-6914 describes a directory traversal vulnerability within the Dir.mktmpdir method of Ruby's tmpdir library, affecting Ruby versions prior to 2.2.10, 2.3.7, 2.4.4, 2.5.1, and 2.6.0-preview1, as well as distributions like Canonical, Debian, and Red Hat. An attacker can exploit this flaw by including ".." in the prefix argument, potentially leading to the creation of arbitrary directories or files. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity and no user interaction required, allowing for high integrity impact without affecting confidentiality or availability. Its EPSS score is low, suggesting a limited probability of exploitation in the wild. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a lack of widespread attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.2.0, < 2.2.10CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
>= 2.3.0, < 2.3.7CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
>= 2.4.0, < 2.4.4CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
>= 2.5.0, < 2.5.1CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
2.6.0CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:2.6.0:preview1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.