puppetlabs / puppet-runtime

runtime dependencies for Vanagon projects
Apache License 2.0
5 stars 88 forks source link

(PA-6282) RDoc vulnerability in Puppet7/Ruby 2.7.8 (CVE-2024-27281) #907

Closed imaqsood closed 3 months ago

imaqsood commented 3 months ago

References

Ruby disclosed on HackerOne: RCE by parsing .rdoc_options in RDoc Specifically:

0001-Filter-marshaled-objects-ruby30.patch (F3085308)

0001-Use-safe_load-and-safe_load_file-for-rdoc_options.patch (F3085309)

https://git.launchpad.net/ubuntu/+source/ruby2.7/commit/?id=7584287c1cf59926252197badedde2cbc08e084c

Testing Done