RubySec

Providing security resources for the Ruby community

CVE-2014-9489 (gollum): gollum and gollum-lib allow remote authenticated users to execute arbitrary code

ADVISORIES

GEM

gollum

SEVERITY

CVSS v3.x: 8.8 (High)

CVSS v2.0: 6.5 (Medium)

PATCHED VERSIONS

  • >= 3.1.1

DESCRIPTION

The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string master is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the -O or --open-files-in-pager flags.

RELATED