Back to Database
Status published
Medium
CVE-2019-15845
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4...
Vulnerability Description
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-15845
Credits & Attribution
No credits recorded in the NVD database.
References
- https://hackerone.com/reports/449617
- https://lists.debian.org/debian-lts-announce/2019/11/msg00025.html
- https://usn.ubuntu.com/4201-1/
- https://seclists.org/bugtraq/2019/Dec/31
- https://seclists.org/bugtraq/2019/Dec/32
- https://www.debian.org/security/2019/dsa-4587
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://security.gentoo.org/glsa/202003-06
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00041.html
More from ruby-lang
View All →CVE-2025-27221
In the URI gem before 1.0.3 for Ruby, the URI...
Low
3.2
CVE-2025-27220
In the CGI gem before 0.4.2 for Ruby, a Regular...
Medium
4
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse...
Medium
5.8
CVE-2022-28739
There is a buffer over-read in Ruby before 2.6.10, 2.7.x...
High
7.5
CVE-2022-28738
A double free was found in the Regexp compiler in...
Critical
9.8
Affected Vendor
ruby-lang
View all reports →Affected Software
ruby, ubuntu linux
Vulnerable Versions:
2.4.0, 2.5.0, 2.6.0, 16.04, 18.04, 19.04, 19.10
Timeline
Official Publish:
November 26th, 2019
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.