Description
The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.
Remediation
References
Related Vulnerabilities
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-3723)
WordPress Plugin Events Manager Cross-Site Scripting (5.9.5)
WordPress Plugin Survey Maker-Best WordPress Survey Cross-Site Scripting (2.0.6)
WordPress Plugin Video Player Unspecified Vulnerability (1.1.4)