Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 710980 (CVE-2020-8130)

Summary: <dev-ruby/rake-12.3.3: command injection vulnerability (CVE-2020-8130)
Product: Gentoo Security Reporter: Thomas Deutschmann (RETIRED) <whissi>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: ruby
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://hackerone.com/reports/651518
Whiteboard: B2 [noglsa cve]
Package list:
Runtime testing required: ---

Description Thomas Deutschmann (RETIRED) gentoo-dev 2020-02-27 18:25:20 UTC
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

Upstream patch:

https://github.com/ruby/rake/commit/5b8f8fc41a5d7d7d6a5d767e48464c60884d3aee
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2020-02-27 18:27:16 UTC
GLSA vote: Note!

Repository is clean, all done.