Skip to content

Commit 9ffd245

Browse files
jasnowRubySec CI
authored and
RubySec CI
committed
Updated advisory posts against rubysec/ruby-advisory-db@5070808
1 parent a851d26 commit 9ffd245

File tree

1 file changed

+5
-3
lines changed

1 file changed

+5
-3
lines changed

advisories/_posts/2023-03-27-CVE-2023-28102.md

+5-3
Original file line numberDiff line numberDiff line change
@@ -7,19 +7,21 @@ categories:
77
advisory:
88
gem: discordrb
99
cve: 2023-28102
10+
ghsa: 8832-4mm5-x2r6
1011
url: https://securitylab.github.com/advisories/GHSL-2022-094_discordrb
1112
title: 'GHSL-2022-094: Remote Code Execution in discordrb'
1213
date: 2023-03-27
1314
description: |
14-
The encode_file method may lead to remote code execution (RCE) if
15-
invoked with untrusted user-controlled data.
15+
The encode_file method may lead to remote code execution
16+
(RCE) if invoked with untrusted user-controlled data.
1617
cvss_v3: 9.6
1718
patched_versions:
1819
- ">= 3.4.3"
1920
related:
2021
url:
2122
- https://nvd.nist.gov/vuln/detail/CVE-2023-28102
22-
- https://github.com/shardlab/discordrb/commit/91e13043ffa89227c3fcdc3408f06da237d28c95
2323
- https://securitylab.github.com/advisories/GHSL-2022-094_discordrb
24+
- https://github.com/shardlab/discordrb/commit/91e13043ffa89227c3fcdc3408f06da237d28c95
2425
- https://rubygems.org/gems/discordrb
26+
- https://github.com/advisories/GHSA-8832-4mm5-x2r6
2527
---

0 commit comments

Comments
 (0)