CVE-2019-8320
Estado: ModificadaAlta (7.4)—
A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
- Puntuación base: 7.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.19%
- Percentil entre todas las CVEs puntuadas: 91
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
- https://access.redhat.com/errata/RHSA-2019:1429
- https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html
- https://hackerone.com/reports/317321
- https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
- https://access.redhat.com/errata/RHSA-2019:1429
- https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html
- https://hackerone.com/reports/317321
- https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-8320",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 8.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 9.2,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.4,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 5.2,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-06-06T15:29:01.420",
"references": [
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html",
"source": "cve@mitre.org"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1429",
"source": "cve@mitre.org"
},
{
"url": "https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://hackerone.com/reports/317321",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://access.redhat.com/errata/RHSA-2019:1429",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://hackerone.com/reports/317321",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system."
},
{
"lang": "es",
"value": "Fue encontrado un problema de salto de directorio (Directory Traversal) en RubyGems versión 2.7.6 y posterior hasta la versión 3.0.2. Antes de crear nuevos directorios o tocar archivos (que ahora incluyen el código path-checking para symlinks), se suprimiría el destino apuntado. Si ese destino estaba oculto detrás de un symlink, una gema maliciosa podría suprimir archivos arbitrarios en la máquina del usuario, presumiendo que el atacante podría adivinar las paths. Dada la frecuencia con que la gema se ejecuta como sudo, y cómo son las paths predecibles en los sistemas modernos (/tmp, /usr, etc.), esto podría probablemente conducir a la pérdida de datos o a un sistema inutilizable."
}
],
"lastModified": "2026-06-17T02:41:50.463",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:rubygems:rubygems:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1F19DA38-964A-4AE9-9BB5-1359F1BF1F0B",
"versionEndIncluding": "3.0.2",
"versionStartIncluding": "2.7.6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}