Known vulnerabilities in rh-ruby23-ruby (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rh-ruby23-ruby_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 12
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rh-ruby23-ruby (Red Hat package) rh-ruby23-ruby (Red Hat package) is affected by 12 known vulnerabilities: 2 high, 2 medium, 8 low Critical High Medium Low

Vulnerabilities (12)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU20189 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-8324
CWE-94 Medium
No
No
2.3.8-70.el6, 2.3.8-70.el7 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 11 more
#VU10848 - Command injection
CVE-2017-17790
CWE-77 Low
No
No
2.3.6-67.el6, 2.3.6-67.el7 06.03.2018 SB2018011015
SB2018040507
SB2018080117
and 8 more
#VU9718 - Command injection
CVE-2017-17405
CWE-77 High
Available
No
2.3.6-67.el6, 2.3.6-67.el7 22.12.2017 SB2017121408
SB2017122207
SB2018010413
and 11 more
#VU8815 - Deserialization of Untrusted Data
CVE-2017-0903
CWE-502 High
No
No
2.3.6-67.el6, 2.3.6-67.el7 13.10.2017 SB2017101301
SB2017111201
SB2017121902
and 10 more
#VU8449 - Improper input validation
CVE-2017-14033
CWE-20 Low
No
No
2.3.6-67.el6, 2.3.6-67.el7 15.09.2017 SB2017091505
SB2017100602
SB2017091810
and 15 more
#VU8448 - Exposure of sensitive information to an unauthorized actor
CVE-2017-10784
CWE-200 Low
No
No
2.3.6-67.el6, 2.3.6-67.el7 15.09.2017 SB2017091505
SB2017100602
SB2017091810
and 17 more
#VU8447 - Improper input validation
CVE-2017-0898
CWE-20 Low
No
No
2.3.6-67.el6, 2.3.6-67.el7 15.09.2017 SB2017091505
SB2017100602
SB2017091810
and 16 more
#VU8123 - Exposure of sensitive information to an unauthorized actor
CVE-2017-14064
CWE-200 Low
No
No
2.3.6-67.el6, 2.3.6-67.el7 06.09.2017 SB2017090606
SB2017091505
SB2017100602
and 16 more
#VU8058 - Improper Access Control
CVE-2017-0902
CWE-284 Low
No
No
2.3.6-67.el6, 2.3.6-67.el7 31.08.2017 SB2017083105
SB2017090606
SB2017090607
and 17 more
#VU8057 - Improper input validation
CVE-2017-0901
CWE-20 Medium
Available
No
2.3.6-67.el6, 2.3.6-67.el7 31.08.2017 SB2017083105
SB2017090606
SB2017090607
and 18 more
#VU8056 - Improper Access Control
CVE-2017-0899
CWE-284 Low
No
No
2.3.6-67.el6, 2.3.6-67.el7 31.08.2017 SB2017083105
SB2017090606
SB2017090607
and 16 more
#VU8055 - Improper input validation
CVE-2017-0900
CWE-20 Low
No
No
2.3.6-67.el6, 2.3.6-67.el7 31.08.2017 SB2017083105
SB2017090606
SB2017090607
and 16 more