gollum and gollum-lib allow remote authenticated users to execute arbitrary code
High severity
GitHub Reviewed
Published
Nov 16, 2017
to the GitHub Advisory Database
•
Updated Nov 10, 2023
Description
Published by the National Vulnerability Database
Oct 17, 2017
Published to the GitHub Advisory Database
Nov 16, 2017
Reviewed
Jun 16, 2020
Last updated
Nov 10, 2023
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string
master
is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the-O
or--open-files-in-pager
flags.References