CVE-2014-9489
17.10.2017, 14:29
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the -O or --open-files-in-pager flags.Enginsight
Vendor | Product | Version |
---|---|---|
gollum_project | gollum | 𝑥 ≤ 3.1.0 |
gollum_project | gollum-lib | 𝑥 ≤ 4.0.0 |
gollum_project | grit_adapter | 𝑥 ≤ 0.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References