Known vulnerabilities in rh-ruby24-ruby (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:rh-ruby24-ruby_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 8
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting rh-ruby24-ruby (Red Hat package) rh-ruby24-ruby (Red Hat package) is affected by 8 known vulnerabilities: 1 high, 1 medium, 6 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU20194 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8321
CWE-79 Low
No
No
2.4.6-92.el6, 2.4.6-92.el7 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 9 more
#VU20193 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2019-8320
CWE-22 Low
No
No
2.4.6-92.el6, 2.4.6-92.el7 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 8 more
#VU20192 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8323
CWE-79 Low
No
No
2.4.6-92.el6, 2.4.6-92.el7 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20191 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8322
CWE-79 Low
No
No
2.4.6-92.el6, 2.4.6-92.el7 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20190 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-8325
CWE-79 Low
No
No
2.4.6-92.el6, 2.4.6-92.el7 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 10 more
#VU20189 - Improper Control of Generation of Code ('Code Injection')
CVE-2019-8324
CWE-94 Medium
No
No
2.4.6-92.el6, 2.4.6-92.el7 13.08.2019 SB2019081320
SB2019061706
SB2019072108
and 11 more
#VU10848 - Command injection
CVE-2017-17790
CWE-77 Low
No
No
2.4.3-90.el6, 2.4.3-90.el7 06.03.2018 SB2018011015
SB2018040507
SB2018080117
and 8 more
#VU9718 - Command injection
CVE-2017-17405
CWE-77 High
Available
No
2.4.3-90.el6, 2.4.3-90.el7 22.12.2017 SB2017121408
SB2017122207
SB2018010413
and 11 more