Advisories ยป MGASA-2021-0124

Updated ruby-mechanize packages fix a security vulnerability

Publication date: 12 Mar 2021
Modification date: 12 Mar 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-21289

Description

In Mechanize, from v2.0.0 until v2.7.7, there is a command injection
vulnerability. Affected versions of Mechanize allow for OS commands to be
injected using several classes' methods which implicitly use Ruby's Kernel#open
method (CVE-2021-21289).
                

References

SRPMS

7/core

8/core