Bugzilla – Bug 1164804
VUL-0: CVE-2020-8130: rubygem-rake: command injection when supplying a filename that begins with the pipe character
Last modified: 2024-05-06 17:37:38 UTC
CVE-2020-8130 There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8130 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8130 https://hackerone.com/reports/651518
Tracked SLE12 as affected. Steps for reproducing and the fix is available at [1] [1] https://hackerone.com/reports/651518
SUSE-SU-2020:0737-1: An update that fixes 7 vulnerabilities is now available. Category: security (important) Bug References: 1140844,1152990,1152992,1152994,1152995,1162396,1164804 CVE References: CVE-2012-6708,CVE-2015-9251,CVE-2019-15845,CVE-2019-16201,CVE-2019-16254,CVE-2019-16255,CVE-2020-8130 Sources used: SUSE Linux Enterprise Server for SAP 15 (src): ruby2.5-2.5.7-4.8.1 SUSE Linux Enterprise Server 15-LTSS (src): ruby2.5-2.5.7-4.8.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): ruby2.5-2.5.7-4.8.1 SUSE Linux Enterprise Module for Basesystem 15-SP1 (src): ruby2.5-2.5.7-4.8.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): ruby2.5-2.5.7-4.8.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): ruby2.5-2.5.7-4.8.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2020:0395-1: An update that fixes 7 vulnerabilities is now available. Category: security (important) Bug References: 1140844,1152990,1152992,1152994,1152995,1162396,1164804 CVE References: CVE-2012-6708,CVE-2015-9251,CVE-2019-15845,CVE-2019-16201,CVE-2019-16254,CVE-2019-16255,CVE-2020-8130 Sources used: openSUSE Leap 15.1 (src): ruby2.5-2.5.7-lp151.4.6.1
Submitted for 12/rubygem-rake.
SUSE-SU-2022:3212-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1164804 CVE References: CVE-2020-8130 JIRA References: Sources used: SUSE Linux Enterprise Module for Containers 12 (src): rubygem-rake-10.3.2-9.7.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.