RubySec

Providing security resources for the Ruby community

CVE-2015-7314 (gollum): gollum Upload File Functionality Permits Arbitrary File Access

ADVISORIES

GEM

gollum

PATCHED VERSIONS

  • >= 4.0.1

DESCRIPTION

The gollum gem contains a flaw in its upload file functionality that can allow arbitrary file access. This occurs due to a lack of type checking when handling temporary files during the upload process.