ruby-git is a Ruby library that can be used to create, read and operate Git repositories. ruby-git contains multiple code injection vulnerabilities. If a repository containing a specially crafted filename is loaded to the product, an arbitrary ruby code may be executed.
Created rubygem-git tracking bugs for this issue: Affects: epel-8 [bug 2159673] Affects: fedora-36 [bug 2159674]
*** Bug 2161642 has been marked as a duplicate of this bug. ***