CVE-2014-9489

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
17/10/2017
Last modified:
20/04/2025

Description

The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki documents, allows remote authenticated users to execute arbitrary code via the -O or --open-files-in-pager flags.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gollum_project:gollum:*:*:*:*:*:*:*:* 3.1.0 (including)
cpe:2.3:a:gollum_project:gollum-lib:*:*:*:*:*:*:*:* 4.0.0 (including)
cpe:2.3:a:gollum_project:grit_adapter:*:*:*:*:*:*:*:* 0.1.0 (including)