Known vulnerabilities in rh-ruby23-ruby (Red Hat package)
Vendor:
Red Hat Inc.
Software:
rh-ruby23-ruby (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:rh-ruby23-ruby_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
12
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU20189 - Improper Control of Generation of Code ('Code Injection') CVE-2019-8324 |
CWE-94 | Medium | 2.3.8-70.el6, 2.3.8-70.el7 | 13.08.2019 |
SB2019081320 SB2019061706 SB2019072108 and 11 more |
||
| #VU10848 - Command injection CVE-2017-17790 |
CWE-77 | Low | 2.3.6-67.el6, 2.3.6-67.el7 | 06.03.2018 |
SB2018011015 SB2018040507 SB2018080117 and 8 more |
||
| #VU9718 - Command injection CVE-2017-17405 |
CWE-77 | High | 2.3.6-67.el6, 2.3.6-67.el7 | 22.12.2017 |
SB2017121408 SB2017122207 SB2018010413 and 11 more |
||
| #VU8815 - Deserialization of Untrusted Data CVE-2017-0903 |
CWE-502 | High | 2.3.6-67.el6, 2.3.6-67.el7 | 13.10.2017 |
SB2017101301 SB2017111201 SB2017121902 and 10 more |
||
| #VU8449 - Improper input validation CVE-2017-14033 |
CWE-20 | Low | 2.3.6-67.el6, 2.3.6-67.el7 | 15.09.2017 |
SB2017091505 SB2017100602 SB2017091810 and 15 more |
||
| #VU8448 - Exposure of sensitive information to an unauthorized actor CVE-2017-10784 |
CWE-200 | Low | 2.3.6-67.el6, 2.3.6-67.el7 | 15.09.2017 |
SB2017091505 SB2017100602 SB2017091810 and 17 more |
||
| #VU8447 - Improper input validation CVE-2017-0898 |
CWE-20 | Low | 2.3.6-67.el6, 2.3.6-67.el7 | 15.09.2017 |
SB2017091505 SB2017100602 SB2017091810 and 16 more |
||
| #VU8123 - Exposure of sensitive information to an unauthorized actor CVE-2017-14064 |
CWE-200 | Low | 2.3.6-67.el6, 2.3.6-67.el7 | 06.09.2017 |
SB2017090606 SB2017091505 SB2017100602 and 16 more |
||
| #VU8058 - Improper Access Control CVE-2017-0902 |
CWE-284 | Low | 2.3.6-67.el6, 2.3.6-67.el7 | 31.08.2017 |
SB2017083105 SB2017090606 SB2017090607 and 17 more |
||
| #VU8057 - Improper input validation CVE-2017-0901 |
CWE-20 | Medium | 2.3.6-67.el6, 2.3.6-67.el7 | 31.08.2017 |
SB2017083105 SB2017090606 SB2017090607 and 18 more |
||
| #VU8056 - Improper Access Control CVE-2017-0899 |
CWE-284 | Low | 2.3.6-67.el6, 2.3.6-67.el7 | 31.08.2017 |
SB2017083105 SB2017090606 SB2017090607 and 16 more |
||
| #VU8055 - Improper input validation CVE-2017-0900 |
CWE-20 | Low | 2.3.6-67.el6, 2.3.6-67.el7 | 31.08.2017 |
SB2017083105 SB2017090606 SB2017090607 and 16 more |