Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67986

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.

A flaw was found in amazing_print. This vulnerability allows an attacker to inject and execute arbitrary Ruby code within the host process. The flaw occurs when the grep method is called with a block, and a specially crafted method name containing Ruby interpolation syntax is processed. Successful exploitation requires the attacker to influence dynamic method names through an application path.

Отчет

Red Hat Satellite includes the rubygem-amazing_print package as a dependency of the hammer CLI tool. While the vulnerable code exists in the shipped version, the specific code path that enables exploitation — calling grep with a block on method arrays — is not used by Satellite or any of its components. The gem is used solely for debug-level object formatting. As a result, this vulnerability is not exploitable in Red Hat Satellite as shipped.

Меры по смягчению последствий

No action is required. The vulnerable code path in amazing_print is not reachable through normal Satellite operation. Customers who have developed custom scripts or plugins that call amazing_print's method array grep with a block should avoid passing untrusted input into method introspection until an upstream fix is available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6rubygem-amazing_printNot affected
Red Hat Satellite 6satellite:el8/rubygem-amazing_printNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=2515343amazing_print: amazing_print: Arbitrary code execution via Ruby code injection in AwesomeMethodArray#grep

EPSS

Процентиль: 9%
0.0019
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
ubuntu
19 дней назад

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.

CVSS3: 8.4
nvd
19 дней назад

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.

CVSS3: 8.4
debian
19 дней назад

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c271 ...

CVSS3: 8.4
github
19 дней назад

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a dynamically constructed eval string when grep is called with a block, resulting in Ruby code execution in the host process. Exploitation requires an application path that allows an attacker to influence dynamic method names.

EPSS

Процентиль: 9%
0.0019
Низкий

7.8 High

CVSS3