rubygems-update is vulnerable to Path Traversal
46
Medium Risk
Affected versions of this package are vulnerable to a path traversal during gem extraction. RubyGems rejected absolute paths and .. segments but still followed a pre-existing symlink inside the extraction destination, allowing files written under destination_dir to land outside the intended root. The fix resolves the real path of each extracted file's parent directory and raises a Gem::Package::PathError when the resolved path escapes the destination.
You are affected if you are using a version that falls within the vulnerable range.
rubygems-update is vulnerable to Path Traversal in versions 0.0.1 - 4.0.12.
Upgrade the rubygems-update library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant