CVE-2017-8418

RuboCop 0.48.1 and earlier does not use /tmp in safe way, allowing local users to exploit this to tamper with cache files belonging to other users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
rubocop_projectrubocop
𝑥
≤ 0.48.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rubocop
bullseye
0.89.1+dfsg-1
fixed
sid
1.39.0+dfsg-1
fixed
trixie
1.39.0+dfsg-1
fixed
bookworm
1.39.0+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rubocop
cosmic
not-affected
bionic
not-affected
artful
ignored
zesty
dne
yakkety
dne
xenial
dne
trusty
dne
precise
dne