gollum
A simple, Git-powered wiki with a sweet API and local frontend.
Activity
- Latest release
- 1y ago
- Total releases
- 92
- Cadence
- ~33 days
- Last 12 months
- 0
Details
- License
- MIT
- First release
- Aug 12, 2010
| Version | Released | |
|---|---|---|
6.1.0
minor
|
6.1.0
minor
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
6.0.1
patch
|
6.0.1
patch
Dependencies (24)
+ 16 more
Changelog
Compare changes
|
|
6.0.0
major
|
6.0.0
major
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
5.3.3
patch
|
5.3.3
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
5.3.2
patch
|
5.3.2
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
5.3.1
patch
|
5.3.1
patch
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
5.3.0
minor
|
5.3.0
minor
Dependencies (23)
+ 15 more
Changelog
Compare changes
|
|
5.2.3
patch
|
5.2.3
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
5.2.2
patch
|
5.2.2
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
5.2.1
patch
|
5.2.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
5.2
minor
|
5.2
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
5.1.2
patch
|
5.1.2
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
5.1.1
patch
1 CVE
CVE-2020-35305
GHSA-fj2w-qmjp-3rjm
Jul 16, 2022
Gollum Cross-site Scripting vulnerability via filename parameter to New Page dialog
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog. Affected versions
5.0.0
5.0.1
5.1
5.1.1
Fixed in
5.1.2
References Updated Feb 16, 2024 · Source: OSV.dev |
5.1.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
5.1
minor
1 CVE
CVE-2020-35305
GHSA-fj2w-qmjp-3rjm
Jul 16, 2022
Gollum Cross-site Scripting vulnerability via filename parameter to New Page dialog
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog. Affected versions
5.0.0
5.0.1
5.1
5.1.1
Fixed in
5.1.2
References Updated Feb 16, 2024 · Source: OSV.dev |
5.1
minor
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
5.0.1
patch
1 CVE
CVE-2020-35305
GHSA-fj2w-qmjp-3rjm
Jul 16, 2022
Gollum Cross-site Scripting vulnerability via filename parameter to New Page dialog
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog. Affected versions
5.0.0
5.0.1
5.1
5.1.1
Fixed in
5.1.2
References Updated Feb 16, 2024 · Source: OSV.dev |
5.0.1
patch
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
5.0.0
major
1 CVE
CVE-2020-35305
GHSA-fj2w-qmjp-3rjm
Jul 16, 2022
Gollum Cross-site Scripting vulnerability via filename parameter to New Page dialog
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Cross site scripting (XSS) in gollum 5.0 to 5.1.2 via the filename parameter to the 'New Page' dialog. Affected versions
5.0.0
5.0.1
5.1
5.1.1
Fixed in
5.1.2
References Updated Feb 16, 2024 · Source: OSV.dev |
5.0.0
major
Dependencies (22)
+ 14 more
Changelog
Compare changes
|
|
4.1.4
patch
|
4.1.4
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
4.1.3
patch
|
4.1.3
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
4.1.2
patch
|
4.1.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
4.1.1
patch
|
4.1.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
4.1.0
minor
|
4.1.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
4.0.1
patch
|
4.0.1
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
4.0.0
major
1 CVE
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev |
4.0.0
major
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.1.3
patch
1 CVE
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev |
3.1.3
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.1.2
patch
1 CVE
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev |
3.1.2
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.1.1
patch
1 CVE
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev |
3.1.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.1.0
minor
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.1.0
minor
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
3.0.0
major
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
3.0.0
major
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
2.7.0
minor
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.7.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.6.0
minor
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.6.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
2.5.2
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.5.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.5.1
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.5.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
2.5.0
minor
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.5.0
minor
Dependencies (7)
Changelog
Compare changes
|
|
2.4.15
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.15
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.4.14
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.14
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.4.13
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.13
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.4.12
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.12
patch
Dependencies (7)
Changelog
Compare changes
|
|
2.4.11
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.11
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.9
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.9
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.8
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.8
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.7
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.7
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.10
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.10
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.6
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.6
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.5
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.5
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.4
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.4
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.2
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.2
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.3
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.3
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.1
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.1
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.4.0
minor
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.4.0
minor
Dependencies (19)
+ 11 more
Changelog
Compare changes
|
|
2.3.8
patch
2 CVEs
CVE-2015-7314
GHSA-m2q3-53fq-7h66
Aug 28, 2018
Gollum Exposure of Sensitive Information
Medium
The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check. Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 58 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
3.1.1
3.1.2
3.1.3
4.0.0
Fixed in
4.0.1
References Updated Dec 05, 2024 · Source: OSV.dev
CVE-2014-9489
GHSA-q97v-764g-r2rp
Nov 16, 2017
gollum and gollum-lib allow remote authenticated users to execute arbitrary code
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string Affected versions
1.0.0
1.0.1
1.1.0
1.1.1
1.2.0
1.2.1
1.3.0
1.3.1
1.4.2
1.4.3
2.0.0
2.1.0
+ 54 more Show less
2.1.10
2.1.2
2.1.3
2.1.4
2.1.6
2.1.7
2.1.8
2.1.9
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.2.8
2.2.9
2.3.0
2.3.1
2.3.10
2.3.11
2.3.12
2.3.2
2.3.3
2.3.4
2.3.5
2.3.6
2.3.7
2.3.8
2.3.9
2.4.0
2.4.1
2.4.10
2.4.11
2.4.12
2.4.13
2.4.14
2.4.15
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.6.0
2.7.0
3.0.0
3.1.0
Fixed in
3.1.1
References
Updated Feb 16, 2024 · Source: OSV.dev |
2.3.8
patch
Dependencies (19)
+ 11 more
Changelog
Compare changes
|