Description
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.
Remediation
References
Related Vulnerabilities
Apache Tomcat CVE-2019-2684 Vulnerability (CVE-2019-2684)
WordPress Plugin PowerPress Podcasting by Blubrry Cross-Site Scripting (10.0)
Apache HTTP Server Other Vulnerability (CVE-2004-0942)
Oracle JRE CVE-2012-5070 Vulnerability (CVE-2012-5070)
Artifactory Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10324)