GHSA-q97v-764g-r2rp

    Dashboard / Vulnerabilities / GHSA-q97v-764g-r2rp

    GHSA-q97v-764g-r2rp

    Published: 16 Nov 2017Last Modified: 16 Feb 2024
    Aliases:

    Summary: gollum and gollum-lib allow remote authenticated users to execute arbitrary code

    Details: The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string `master` is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the `-O` or `--open-files-in-pager` flags.

    Affected packages

    Package

    Name: gollum

    Purl: pkg:gem/gollum

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.1.1

    Affected versions

    1.0.0
    1.0.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High