Описание
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
Ссылки
- Mailing ListThird Party Advisory
- Permissions RequiredThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Permissions RequiredThird Party Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Одно из
EPSS
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.
An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since ...
RubyGems Escape sequence injection vulnerability in verbose
Уязвимость модуля Gem::UserInteraction системы управления пакетами RubyGems, позволяющая нарушителю нарушить целостность данных
EPSS
7.5 High
CVSS3
5 Medium
CVSS2