The vendor explicitly identifies these products or versions as containing the fix.
- ruby-0:3.3.10-11.el10_0.1.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-0:3.3.10-11.el10_0.1.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-0:3.3.10-11.el10_0.1.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-0:3.3.10-11.el10_0.1.src as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-0:3.3.10-11.el10_0.1.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-bundled-gems-0:3.3.10-11.el10_0.1.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-bundled-gems-0:3.3.10-11.el10_0.1.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-bundled-gems-0:3.3.10-11.el10_0.1.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-bundled-gems-0:3.3.10-11.el10_0.1.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-bundled-gems-debuginfo-0:3.3.10-11.el10_0.1.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-bundled-gems-debuginfo-0:3.3.10-11.el10_0.1.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- ruby-bundled-gems-debuginfo-0:3.3.10-11.el10_0.1.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
- Summary
- A flaw was found in ERB, a templating system for Ruby. An attacker who can trigger deserialization of untrusted data in a Ruby application can bypass existing protections. This vulnerability allows for arbitrary code execution by exploiting specific public methods that evaluate template source code, which were not properly guarded against deserialization attacks.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
