{ "schema_version": "1.4.0", "id": "GHSA-m2q3-53fq-7h66", "modified": "2023-03-14T20:41:45Z", "published": "2018-08-28T22:33:51Z", "aliases": [ "CVE-2015-7314" ], "summary": "Gollum Exposure of Sensitive Information", "details": "The Precious module in gollum before 4.0.1 allows remote attackers to read arbitrary files by leveraging the lack of a certain temporary-file check.", "severity": [], "affected": [ { "package": { "ecosystem": "RubyGems", "name": "gollum" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "fixed": "4.0.1" } ] } ] } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-7314" }, { "type": "WEB", "url": "https://github.com/gollum/gollum/issues/1070" }, { "type": "WEB", "url": "https://github.com/gollum/gollum/commit/ce68a88293ce3b18c261312392ad33a88bb69ea1" }, { "type": "PACKAGE", "url": "https://github.com/gollum/gollum" }, { "type": "WEB", "url": "http://jvn.jp/en/jp/JVN27548431/index.html" }, { "type": "WEB", "url": "http://jvndb.jvn.jp/jvndb/JVNDB-2015-000149" }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2015/09/22/12" } ], "database_specific": { "cwe_ids": [ "CWE-200" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:44:36Z", "nvd_published_at": null } }