{"id":"MGASA-2019-0062","summary":"Updated jruby packages fix security vulnerability","details":"Several vulnerabilities were discovered in jruby. They would allow an\nattacker to use specially crafted gem files to mount cross-site scripting\nattacks, cause denial of service through an infinite loop, write arbitrary\nfiles, or run malicious code (CVE-2018-1000073, CVE-2018-1000074,\nCVE-2018-1000075, CVE-2018-1000076, CVE-2018-1000077, CVE-2018-1000078,\nCVE-2018-1000079).\n","modified":"2026-04-16T01:46:49.832696739Z","published":"2019-02-13T11:08:25Z","upstream":["CVE-2018-1000073","CVE-2018-1000074","CVE-2018-1000075","CVE-2018-1000076","CVE-2018-1000077","CVE-2018-1000078","CVE-2018-1000079"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0062.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=23158"},{"type":"WEB","url":"https://www.debian.org/security/2018/dsa-4219"}],"affected":[{"package":{"name":"jruby","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/jruby?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.7.22-5.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0062.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}