Junglewise Threat Intelligence

CVE-2014-9489: gollum and gollum-lib allow remote authenticated users to execute arbitrary code

CVE-2014-9489 · Severity: low · CVSS 3 · Published 2017-11-16

Technologies: gollum (RubyGems). Vendors: RubyGems.

Executive brief

gollum and gollum-lib allow remote authenticated users to execute arbitrary code

Affected products

  • RubyGems gollum
  • RubyGems gollum-lib

Related threats