Arbitrary File Access Affecting gollum package, versions < 4.0.1
Threat Intelligence
EPSS
0.5% (77th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-GOLLUM-20240
- published 19 Sep 2015
- disclosed 19 Sep 2015
- credit Bart Kamphorst
Introduced: 19 Sep 2015
CVE-2015-7314 Open this link in a new tabOverview
gollum
is a simple, Git-powered wiki with an API and local frontend.
Affected versions of this gem are vulnerable to arbitrary file access via its upload file functionality lacking validation when handling temporary files during the upload process.
References
CVSS Scores
version 3.1