RubySec

Providing security resources for the Ruby community

CVE-2017-8418 (rubocop): RuboCop gem Insecure use of /tmp

RuboCop gem Insecure use of /tmp

Published: May 01, 2017

SECURITY IDENTIFIERS

GEM

rubocop

SEVERITY

CVSS v3.x: 3.3 (Low)

CVSS v2.0: 2.1 (Low)

PATCHED VERSIONS

>= 0.49.0

DESCRIPTION

RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.

RELATED