{"id":"GHSA-3q5q-f79q-7hr2","summary":"High severity vulnerability that affects rubyzip","details":"Withdrawn, accidental duplicate publish.\n\nThe Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses \"../\" pathname substrings to write arbitrary files to the filesystem.","modified":"2024-12-02T05:44:31.025099Z","published":"2018-07-31T18:21:46Z","withdrawn":"2020-06-16T20:55:57Z","database_specific":{"github_reviewed_at":"2020-06-16T20:55:57Z","nvd_published_at":null,"cwe_ids":[],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-5946"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3q5q-f79q-7hr2"}],"affected":[{"package":{"name":"rubyzip","ecosystem":"RubyGems","purl":"pkg:gem/rubyzip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.1"}]}],"versions":["0.5.11","0.5.12","0.5.7","0.5.8","0.5.9","0.9.1","0.9.4","0.9.5","0.9.6.1","0.9.7","0.9.8","0.9.9","1.0.0","1.0.0.beta1","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-3q5q-f79q-7hr2/GHSA-3q5q-f79q-7hr2.json"}}],"schema_version":"1.9.0"}