In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter with TmpDir.
{
"cpe": "cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.7.3"
},
{
"introduced": "3.0.0"
},
{
"fixed": "3.0.1"
}
],
"source": "CPE_FIELD"
}