The netaddr gem before 1.5.3 and 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
References
https://nvd.nist.gov/vuln/detail/CVE-2019-17383
https://github.com/dspinhir…