Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mh37-8c3g-3fgc

Опубликовано: 20 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

RubyGems Escape sequence injection vulnerability in gem owner

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

Пакеты

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

>= 2.6.0, < 2.7.9

2.7.9

Наименование

rubygems-update

rubygems
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.2

3.0.2

EPSS

Процентиль: 49%
0.00254
Низкий

7.5 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 5.3
redhat
больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
nvd
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
debian
около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The g ...

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость команды gem owner системы управления пакетами RubyGems, связанная с выводом содержимого ответа API в стандартный поток вывода, позволяющая нарушителю нарушить целостность данных

EPSS

Процентиль: 49%
0.00254
Низкий

7.5 High

CVSS3

Дефекты

CWE-74