CVE-2019-8320: Path Traversal

Published Mar 25, 2019
·
Updated

A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.

Other sources

A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user’s machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.

Upstream patch:

https://bugs.ruby-lang.org/attachments/7669

References:

https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/ https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html

Red Hat

Affected Software

3 affected componentsFixes available
rubygems/rubygems-update>=3.0.0<3.0.3
3.0.3
rubygems/rubygems-update>=2.7.6<2.7.9
2.7.9
Rubygems RubyGems>=2.7.6<=3.0.2

Event History

Mar 25, 2019
Data Sourced
via Red Hat·06:42 PM
DescriptionSeverityAffected Software
Jun 6, 2019
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
Description
Jun 20, 2019
Advisory Published
04:06 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2019-8320?

CVE-2019-8320 is a Directory Traversal vulnerability discovered in RubyGems 2.7.6 through 3.0.2.

2

How severe is CVE-2019-8320?

CVE-2019-8320 has a severity of 7.4 (High).

3

How does CVE-2019-8320 affect RubyGems?

CVE-2019-8320 affects RubyGems versions 2.7.6 through 3.0.2.

4

What is the remedy for CVE-2019-8320 in RubyGems?

The remedy for CVE-2019-8320 in RubyGems is to upgrade to version 3.0.3.

5

Where can I find more information about CVE-2019-8320?

You can find more information about CVE-2019-8320 at the following references: [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-8320), [RubyGems Blog](https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html), [HackerOne Report](https://hackerone.com/reports/317321).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203