Tempfile on Windows path traversal vulnerability
High severity
GitHub Reviewed
Published
May 6, 2021
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Reviewed
May 6, 2021
Published to the GitHub Advisory Database
May 6, 2021
Published by the National Vulnerability Database
Jul 30, 2021
Last updated
Jan 27, 2023
There is an unintentional directory creation vulnerability in
tmpdir
library bundled with Ruby on Windows. And there is also an unintentional file creation vulnerability in tempfile library bundled with Ruby on Windows, because it uses tmpdir internally.References