CVE-2014-0177
low
CVSS v3
—
CVSS v2
3.6
VIR risk
3.6
Description
Hub Package Arbitrary File Overwrite
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://github.com/github/hub/commit/016ec99d25b1cb83cb4367e541177aa431beb600
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| RubyGems | hub | <>= 1.12.1 | >= 1.12.1 |
| Go | github.com/github/hub | <1.12.1 | 1.12.1 |
| RubyGems | hub | <1.12.1 | 1.12.1 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| github | hub | {"endIncluding":"1.12.0"} | |
References
- https://github.com/mislav/hub/releases/tag/v1.12.1
- http://secunia.com/advisories/58273
- https://github.com/github/hub/commit/016ec99d25b1cb83cb4367e541177aa431beb600
- https://nvd.nist.gov/vuln/detail/CVE-2014-0177
- https://github.com/mislav/hub/commit/016ec99d25b1cb83cb4367e541177aa431beb600
- https://github.com/mislav/hub
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/hub/CVE-2014-0177.yml
CWEs
CWE-310
Verify integrity in audit chain (admin only). AS-IS.