ALSA-2022:0545
Dashboard / Vulnerabilities / ALSA-2022:0545
Summary: Important: ruby:2.5 security update
Details: Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source (CVE-2020-36327) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://errata.almalinux.org/8/ALSA-2022-0545.html, https://vulners.com/cve/CVE-2020-36327
Affected packages
Package
Name: ruby
Purl: pkg:rpm/almalinux/ruby
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -2.5.9-107.module_el8.5.0+2625+ec418553
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
