Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, an attacker controlling the unpacking format (similar to format string vulnerabilities) can trigger a buffer under-read in the String#unpack method, resulting in a massive and controlled information disclosure.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ruby 安全漏洞
Vulnerability Description
Ruby是日本软件开发者松本行弘所研发的一种跨平台、面向对象的动态类型编程语言。 Ruby中的String#unpack方法存在信息泄露漏洞,该漏洞源于程序没有正确的处理‘@’格式区分符。远程攻击者可通过发送请求,提交恶意输入利用该漏洞访问敏感信息。以下版本受到影响:Ruby 2.2.10之前的版本,2.3.7之前的2.3.x版本,2.4.4之前的2.4.x版本,2.5.1之前的2.5.x版本,2.6.0-preview1版本。
CVSS Information
N/A
Vulnerability Type
N/A