RubySec

Providing security resources for the Ruby community

CVE-2015-7314 (gollum): gollum Upload File Functionality Permits Arbitrary File Access

gollum Upload File Functionality Permits Arbitrary File Access

Published: September 20, 2015

SECURITY IDENTIFIERS

GEM

gollum

PATCHED VERSIONS

>= 4.0.1

DESCRIPTION

The gollum gem contains a flaw in its upload file functionality that can allow arbitrary file access. This occurs due to a lack of type checking when handling temporary files during the upload process.