{"id":"CVE-2015-7314","aliases":[],"url":"https://o3.security/vulnerability/CVE-2015-7314","summary":"Gollum Exposure of Sensitive Information","details":"The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check.","published":"2018-08-28T22:33:51Z","modified":"2024-12-05T05:29:49.816459Z","cvss":null,"epss":{"score":0.01876,"percentile":0.77252,"asOf":"2026-07-28"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"RubyGems","name":"gollum","fixedVersion":"4.0.1"}],"fix":{"url":"https://github.com/gollum/gollum/commit/ce68a88293ce3b18c261312392ad33a88bb69ea1","label":"gollum/gollum@ce68a88"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-7314"},{"type":"WEB","url":"https://github.com/gollum/gollum/issues/1070"},{"type":"WEB","url":"https://github.com/gollum/gollum/commit/ce68a88293ce3b18c261312392ad33a88bb69ea1"},{"type":"PACKAGE","url":"https://github.com/gollum/gollum"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN27548431/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2015-000149"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/09/22/12"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-05T05:29:49.816459Z"}}