CVE-2019-15845: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 3.3% chance of exploitation in the next 30 days.
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Ruby-Lang Ruby: from 2.4.0, up to and including 2.4.7; from 2.5.0, up to and including 2.5.6; from 2.6.0, up to and including 2.6.4
Published 2019-11-26. Last modified 2026-06-17.