Vulnerability Details CVE-2018-8779
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open methods are not checked for null characters. It may be connected to an unintended socket.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.01
EPSS Ranking 76.5%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2018-8779
-
cpe:2.3:a:ruby-lang:ruby:2.2.0
-
cpe:2.3:a:ruby-lang:ruby:2.2.1
-
cpe:2.3:a:ruby-lang:ruby:2.2.2
-
cpe:2.3:a:ruby-lang:ruby:2.2.3
-
cpe:2.3:a:ruby-lang:ruby:2.2.4
-
cpe:2.3:a:ruby-lang:ruby:2.2.5
-
cpe:2.3:a:ruby-lang:ruby:2.2.6
-
cpe:2.3:a:ruby-lang:ruby:2.2.7
-
cpe:2.3:a:ruby-lang:ruby:2.2.8
-
cpe:2.3:a:ruby-lang:ruby:2.2.9
-
cpe:2.3:a:ruby-lang:ruby:2.3.0
-
cpe:2.3:a:ruby-lang:ruby:2.3.1
-
cpe:2.3:a:ruby-lang:ruby:2.3.2
-
cpe:2.3:a:ruby-lang:ruby:2.3.3
-
cpe:2.3:a:ruby-lang:ruby:2.3.4
-
cpe:2.3:a:ruby-lang:ruby:2.3.5
-
cpe:2.3:a:ruby-lang:ruby:2.3.6
-
cpe:2.3:a:ruby-lang:ruby:2.4.0
-
cpe:2.3:a:ruby-lang:ruby:2.4.1
-
cpe:2.3:a:ruby-lang:ruby:2.4.2
-
cpe:2.3:a:ruby-lang:ruby:2.4.3
-
cpe:2.3:a:ruby-lang:ruby:2.5.0
-
cpe:2.3:a:ruby-lang:ruby:2.6.0
-
cpe:2.3:o:canonical:ubuntu_linux:14.04
-
cpe:2.3:o:canonical:ubuntu_linux:16.04
-
cpe:2.3:o:canonical:ubuntu_linux:17.10
-
cpe:2.3:o:debian:debian_linux:7.0
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0