
Cloud Vulnerability DB
A community-led vulnerabilities database
Narou (aka Narou.rb) before version 3.8.0 contains a Ruby Code Injection vulnerability (CVE-2021-35514) that was discovered and disclosed on June 28, 2021. The vulnerability affects the Narou.rb application, which is a tool for managing novel downloads. The issue allows attackers to inject and execute arbitrary Ruby code via the title name or author name of a novel (NVD, RyotaK Advisory).
The vulnerability is classified as CWE-94 (Code Injection) and received a CVSS v3.1 Base Score of 9.8 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). The issue stems from insufficient validation of novel information, specifically in the handling of title names and author names, which could be crafted to contain malicious Ruby code that would then be executed by the application (NVD).
The vulnerability allows attackers to execute arbitrary code on the system where Narou.rb runs. Due to the critical CVSS score and the nature of code injection vulnerabilities, this could lead to complete system compromise, allowing attackers to execute commands with the same privileges as the Narou.rb application (NVD).
The vulnerability can be exploited by crafting a malicious novel with specially formatted title or author names containing Ruby code. The attack requires no special privileges or user interaction, making it highly exploitable (RyotaK Advisory).
The vulnerability was fixed in Narou.rb version 3.8.0, released on June 27, 2021. Users are strongly recommended to upgrade to version 3.8.0 or later to address this security issue. No workarounds are available for users who cannot upgrade (Narou Changelog).
The vulnerability was discovered and reported by security researcher RyotaK, who was acknowledged in the project's changelog. The Narou.rb maintainers responded promptly by releasing a fix in version 3.8.0 (Narou Changelog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."