CVE-2017-5946: Directory traversal vulnerability
(updated )
The Zip::File
component in the rubyzip gem for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip
files, an attacker can upload a malicious file that uses ../
pathname substrings to write arbitrary files to the filesystem.
References
Detect and mitigate CVE-2017-5946 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →