7.5

CVE-2008-3655

Exploit

Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical variables and methods at various safe levels, which allows context-dependent attackers to bypass intended access restrictions via (1) untrace_var, (2) $PROGRAM_NAME, and (3) syslog at safe level 4, and (4) insecure methods at safe levels 1 through 3.

Data is provided by the National Vulnerability Database (NVD)
Ruby-langRuby Version <= 1.8.5
Ruby-langRuby Version1.6.8
Ruby-langRuby Version1.8.0
Ruby-langRuby Version1.8.1
Ruby-langRuby Version1.8.1 Update-9
Ruby-langRuby Version1.8.2
Ruby-langRuby Version1.8.2 Updatepreview2
Ruby-langRuby Version1.8.2 Updatepreview3
Ruby-langRuby Version1.8.2 Updatepreview4
Ruby-langRuby Version1.8.3
Ruby-langRuby Version1.8.3 Updatepreview1
Ruby-langRuby Version1.8.3 Updatepreview2
Ruby-langRuby Version1.8.3 Updatepreview3
Ruby-langRuby Version1.8.4
Ruby-langRuby Version1.8.4 Updatepreview1
Ruby-langRuby Version1.8.4 Updatepreview2
Ruby-langRuby Version1.8.4 Updatepreview3
Ruby-langRuby Version1.8.5 Updatep11
Ruby-langRuby Version1.8.5 Updatep113
Ruby-langRuby Version1.8.5 Updatep115
Ruby-langRuby Version1.8.5 Updatep12
Ruby-langRuby Version1.8.5 Updatep2
Ruby-langRuby Version1.8.5 Updatep35
Ruby-langRuby Version1.8.5 Updatepreview1
Ruby-langRuby Version1.8.5 Updatepreview2
Ruby-langRuby Version1.8.5 Updatepreview3
Ruby-langRuby Version1.8.5 Updatepreview4
Ruby-langRuby Version1.8.5 Updatepreview5
Ruby-langRuby Version1.8.6
Ruby-langRuby Version1.8.6 Updatep110
Ruby-langRuby Version1.8.6 Updatep111
Ruby-langRuby Version1.8.6 Updatep114
Ruby-langRuby Version1.8.6 Updatep230
Ruby-langRuby Version1.8.6 Updatep286
Ruby-langRuby Version1.8.6 Updatep36
Ruby-langRuby Version1.8.6 Updatepreview1
Ruby-langRuby Version1.8.6 Updatepreview2
Ruby-langRuby Version1.8.6 Updatepreview3
Ruby-langRuby Version1.8.7
Ruby-langRuby Version1.8.7 Updatep17
Ruby-langRuby Version1.8.7 Updatep22
Ruby-langRuby Version1.8.7 Updatep71
Ruby-langRuby Version1.8.7 Updatepreview1
Ruby-langRuby Version1.8.7 Updatepreview2
Ruby-langRuby Version1.8.7 Updatepreview3
Ruby-langRuby Version1.8.7 Updatepreview4
Ruby-langRuby Version1.9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 37.12% 0.971
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P