MGASA-2021-0124 - Updated ruby-mechanize packages fix a security vulnerability

Publication date: 12 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0124.html
Type: security
Affected Mageia releases: 7, 8
CVE: CVE-2021-21289

In Mechanize, from v2.0.0 until v2.7.7, there is a command injection
vulnerability. Affected versions of Mechanize allow for OS commands to be
injected using several classes' methods which implicitly use Ruby's Kernel#open
method (CVE-2021-21289).

References:
- https://bugs.mageia.org/show_bug.cgi?id=28448
- https://www.debian.org/lts/security/2021/dla-2561
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21289

SRPMS:
- 7/core/ruby-mechanize-2.7.6-2.1.mga7
- 8/core/ruby-mechanize-2.7.6-3.1.mga8

Mageia 2021-0124: ruby-mechanize security update

In Mechanize, from v2.0.0 until v2.7.7, there is a command injection vulnerability

Summary

In Mechanize, from v2.0.0 until v2.7.7, there is a command injection vulnerability. Affected versions of Mechanize allow for OS commands to be injected using several classes' methods which implicitly use Ruby's Kernel#open method (CVE-2021-21289).

References

- https://bugs.mageia.org/show_bug.cgi?id=28448

- https://www.debian.org/lts/security/2021/dla-2561

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-21289

Resolution

MGASA-2021-0124 - Updated ruby-mechanize packages fix a security vulnerability

SRPMS

- 7/core/ruby-mechanize-2.7.6-2.1.mga7

- 8/core/ruby-mechanize-2.7.6-3.1.mga8

Severity
Publication date: 12 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0124.html
Type: security
CVE: CVE-2021-21289

Related News