Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8130

Опубликовано: 24 фев. 2020
Источник: debian

Описание

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rakefixed12.3.3-1package
rakefixed12.3.1-3+deb10u1busterpackage
rakefixed10.5.0-2+deb9u1stretchpackage

Примечания

  • https://hackerone.com/reports/651518

  • Fixed by: https://github.com/ruby/rake/commit/5b8f8fc41a5d7d7d6a5d767e48464c60884d3aee (v12.3.3)

Связанные уязвимости

CVSS3: 6.4
ubuntu
почти 6 лет назад

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

CVSS3: 6.4
redhat
больше 6 лет назад

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

CVSS3: 6.4
nvd
почти 6 лет назад

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

msrc
4 месяца назад

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.

suse-cvrf
больше 3 лет назад

Security update for rubygem-rake