CVE-2019-17383: Netaddr Project Netaddr

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.

Affected products

  • Netaddr Project Netaddr: from 1.5.0, before 1.5.3 (fixed in 1.5.3); from 2.0, before 2.0.4 (fixed in 2.0.4)

Published 2019-10-09. Last modified 2026-06-17.