{"id":"CVE-2015-3649","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-3649","summary":"open-uri-cached Gem for Ruby Unsafe Temporary File Creation Enables Code Execution","details":"The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing \"openuri-\" followed by a crafted UID, and putting Ruby code in said directory once a metafile is created.","published":"2022-05-13T01:13:48Z","modified":"2024-02-20T05:32:37.867211Z","cvss":{"score":7.8,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"open-uri-cached","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3649"},{"type":"WEB","url":"https://github.com/tigris/open-uri-cached/issues/8"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/open-uri-cached/CVE-2015-3649.yml"},{"type":"PACKAGE","url":"https://github.com/tigris/open-uri-cached"},{"type":"WEB","url":"https://github.com/tigris/open-uri-cached/blob/master/lib/open-uri/cached.rb"},{"type":"WEB","url":"https://web.archive.org/web/20210119122105/http://www.securityfocus.com/bid/74469"},{"type":"WEB","url":"http://seclists.org/oss-sec/2015/q2/373"},{"type":"WEB","url":"http://www.benjaminfleischer.com/2013/03/20/yaml-and-security-in-ruby"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/05/06/2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-02-20T05:32:37.867211Z"}}