#VU11628 Improper input validation in RubyGems - CVE-2018-1000077
Published: April 9, 2018 / Updated: April 10, 2018
RubyGems
Ruby
Description
The vulnerability allows a remote unauthenticated attacker to write arbitrary files on the target system.
The weakness exists due to improper URL validation of the specification homepage attribute. A remote attacker can trick the victim into installing a malicious RubyGems gem and set an invalid homepage URL.