The diff_pp function in lib/gauntlet_rubyparser.rb in the ruby_parser gem 3.1.1 and earlier for Ruby allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| ruby_parser(RubyGems) | 2.0.2 | 3.1.2 | N/A |
CVSS Metrics