CVE-2017-0901: Input Validation
Published Aug 31, 2017
·Updated
Last updated 11 July 2025
Other sources
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
Upstream patch:
https://github.com/rubygems/rubygems/commit/ad5c0a53a86ca5b218c7976765c0365b91d22cb2
Bug report:
https://hackerone.com/reports/243156
External References:
http://blog.rubygems.org/2017/08/27/2.6.13-released.html
— Red Hat
Affected Software
21 affected componentsFixes available
redhat/rubygems<2.6.13
2.6.13
redhat/ruby<2.4.2
2.4.2
redhat/ruby<2.2.8
2.2.8
redhat/ruby<2.3.5
2.3.5
Rubygems RubyGems<=2.6.12
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.4
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Server Tus=7.4
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Workstation=7.0
debian/rubygems
3.2.5-23.2.5-2+deb11u13.3.15-2+deb12u13.6.7-2
Remediation
Patch Available
Patch Available
Event History
Aug 31, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·10:23 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·07:39 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:40 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-0901.
2
What is the severity of CVE-2017-0901?
The severity of CVE-2017-0901 is high, with a severity value of 7.5.
3
How does CVE-2017-0901 affect RubyGems?
CVE-2017-0901 affects RubyGems version 2.6.12 and earlier.
4
What is the impact of CVE-2017-0901?
CVE-2017-0901 allows a maliciously crafted gem to potentially overwrite any file on the filesystem.
5
How can I fix CVE-2017-0901?
To fix CVE-2017-0901, update RubyGems to version 2.6.13 or later.