Symlink File Overwrite Affecting ciborg package, versions >= 0


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RUBY-CIBORG-20179
  • published29 Jun 2014
  • disclosed29 Jun 2014
  • creditUnknown

Introduced: 29 Jun 2014

CVE-2014-5003  (opens in a new tab)
CWE-208  (opens in a new tab)

Overview

ciborg makes it easy to spin up a CI instance in the cloud. Affected versions of this Gem are vulnerable to overwrite an arbitrary files.

Details

ciborg Gem for Ruby contains a flaw as default.rb creates temporary files insecurely. It is possible for a local attacker to use a symlink attack against the /tmp/perlbrew-installer file to cause the program to unexpectedly overwrite an arbitrary file.

CVSS Scores

version 3.1