rpm package
almalinux/rubygem-psych
pkg:rpm/almalinux/rubygem-psych
Vulnerabilities (42)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-36327 | Hig | 8.8 | < 3.1.0-137.module_el8.4.0+2515+f744ca41 | 3.1.0-137.module_el8.4.0+2515+f744ca41 | Apr 29, 2021 | Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another | |
| CVE-2019-19012 | Cri | 9.8 | < 3.0.2-114.module_el8.10.0+3991+5e651d4e | 3.0.2-114.module_el8.10.0+3991+5e651d4e | Nov 17, 2019 | An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a d |
- affected < 3.1.0-137.module_el8.4.0+2515+f744ca41fixed 3.1.0-137.module_el8.4.0+2515+f744ca41
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another
- affected < 3.0.2-114.module_el8.10.0+3991+5e651d4efixed 3.0.2-114.module_el8.10.0+3991+5e651d4e
An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a d
Page 3 of 3