ruby2.6

Link package | bugs open | bugs closed | Wiki | GitHub | web search
Description Unknown
Version Removed

Open

Group Affected Fixed Severity Status Ticket
AVG-2557 2.6.8-2 Medium Unknown
Issue Group Severity Remote Type Description
CVE-2021-41819 AVG-2557 Medium Yes Content spoofing
A security issue has been found in Ruby before versions 3.0.3, 2.7.5 and 2.6.9. A cookie prefix spoofing vulnerability was discovered in CGI::Cookie.parse...
CVE-2021-41817 AVG-2557 Low Yes Denial of service
A security issue has been found in Ruby before versions 3.0.3, 2.7.5 and 2.6.9. In the Ruby "date" gem before versions 3.2.1, 3.1.2, 3.0.2, and 2.0.1, there...

Resolved

Group Affected Fixed Severity Status Ticket
AVG-2140 2.6.7-1 2.6.8-1 High Fixed
Issue Group Severity Remote Type Description
CVE-2021-32066 AVG-2140 High Yes Silent downgrade
A security issue has been discovered in Ruby before versions 3.0.2, 2.7.4 and 2.6.8. Net::IMAP does not raise an exception when StartTLS fails with an...
CVE-2021-31810 AVG-2140 Medium Yes Information disclosure
A security issue has been discovered in Ruby before versions 3.0.2, 2.7.4 and 2.6.8. A malicious FTP server can use the PASV response to trick Net::FTP into...
CVE-2021-31799 AVG-2140 Medium Yes Arbitrary command execution
RDoc before version 6.3.1, as bundled with Ruby before version 2.7.4 and 2.6.8 as well as GitLab before version 14.0.2, used to call Kernel#open to open a...

Advisories

Date Advisory Group Severity Type
14 Jul 2021 ASA-202107-25 AVG-2140 High multiple issues