Ruby_parser-legacy Incorrect Permission Assignment for Critical Resource
High severity
GitHub Reviewed
Published
Oct 25, 2019
to the GitHub Advisory Database
•
Updated Aug 25, 2023
Description
Published by the National Vulnerability Database
Oct 24, 2019
Reviewed
Oct 25, 2019
Published to the GitHub Advisory Database
Oct 25, 2019
Last updated
Aug 25, 2023
The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used, a local user can insert malicious code into the
ruby_parser-legacy-1.0.0/lib/ruby_parser/legacy/ruby_parser.rb
file.References