Files or Directories Accessible to External Parties in bundler - CVE-2019-3881
Published: September 4, 2020 / Updated: January 8, 2021
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to Bundler uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
Affected software
Red Hat Software Collections
GitLab Enterprise Edition
Gitlab Community Edition
Gentoo Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
IBM Cloud Foundry Migration Runtime
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rubygem-bundler
rubygem-bundler-help
dev-ruby/bundler
rh-ruby26-ruby (Red Hat package)
How to mitigate CVE-2019-3881
IBM Cloud Foundry Migration Runtime - update to 4.1.2
GitLab Enterprise Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2
Gitlab Community Edition - addressed in versions 13.5.6, 13.6.4, 13.7.2
rubygem-bundler - update to 2.2.19-1
rubygem-bundler-help - update to 2.2.19-1
dev-ruby/bundler - update to 2.2.33
rh-ruby26-ruby (Red Hat package) - update to 2.6.7-119.el7
External References
Related Security Bulletins
- Privilege escalation in Bundler
- GitLab security update for bundler and curl
- Red Hat Software Collections update for rh-ruby26-ruby
- Red Hat Enterprise Linux 8 update for the ruby:2.6 module
- Multiple vulnerabilities in IBM Cloud Foundry Migration Runtime
- openEuler 20.03 LTS SP2 update for rubygem-bundler
- Gentoo update for Bundler