{"id":"GHSA-hhwc-8g49-j8jx","summary":"Ruby_parser-legacy Incorrect Permission Assignment for Critical Resource","details":"The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used, a local user can insert malicious code into the `ruby_parser-legacy-1.0.0/lib/ruby_parser/legacy/ruby_parser.rb` file.","aliases":["CVE-2019-18409"],"modified":"2023-11-01T04:50:45.645047Z","published":"2019-10-25T19:41:34Z","database_specific":{"cwe_ids":["CWE-732"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2019-10-25T16:26:28Z","nvd_published_at":"2019-10-24T14:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-18409"},{"type":"WEB","url":"https://github.com/zenspider/ruby_parser-legacy/issues/1"},{"type":"WEB","url":"https://brakemanscanner.org/blog/2019/10/14/brakeman-4-dot-7-dot-1-released"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/brakeman/CVE-2019-18409.yml"},{"type":"PACKAGE","url":"https://github.com/zenspider/ruby_parser-legacy"}],"affected":[{"package":{"name":"ruby_parser-legacy","ecosystem":"RubyGems","purl":"pkg:gem/ruby_parser-legacy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.0.0"}]}],"versions":["1.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-hhwc-8g49-j8jx/GHSA-hhwc-8g49-j8jx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}