Medium severity5.4NVD Advisory· Published Dec 26, 2019· Updated Jun 16, 2026
CVE-2013-4318
CVE-2013-4318
Description
File injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
featuresRubyGems | <= 0.3.0 | — |
Affected products
3- cpe:2.3:a:feature_project:feature:0.3.0:*:*:*:*:ruby:*:*
- Features/Featuresv5Range: 0.3.0
Patches
Vulnerability mechanics
References
5- www.openwall.com/lists/oss-security/2013/09/09/10nvdExploitMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-42gq-h7xj-33r4ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2013-4318ghsaADVISORY
- security-tracker.debian.org/tracker/CVE-2013-4318nvdThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/features/CVE-2013-4318.ymlghsaWEB
News mentions
0No linked articles in our index yet.