Логотип exploitDog
bind:"CVE-2019-8324" OR bind:"CVE-2019-8322" OR bind:"CVE-2019-8323" OR bind:"CVE-2019-8325"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-8324" OR bind:"CVE-2019-8322" OR bind:"CVE-2019-8323" OR bind:"CVE-2019-8325"

Количество 30

Количество 30

oracle-oval логотип

ELSA-2019-1235

больше 6 лет назад

ELSA-2019-1235: ruby security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1771-1

больше 6 лет назад

Security update for ruby-bundled-gems-rpmhelper, ruby2.5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1804-1

больше 6 лет назад

Security update for ruby-bundled-gems-rpmhelper, ruby2.5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1570-1

больше 5 лет назад

Security update for ruby2.1

EPSS: Низкий
ubuntu логотип

CVE-2019-8324

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2019-8324

почти 7 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2019-8324

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-8324

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2019:1972

больше 6 лет назад

Important: ruby:2.5 security update

EPSS: Низкий
github логотип

GHSA-76wm-422q-92mq

больше 6 лет назад

Code injection in RubyGems

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2019-1972

больше 6 лет назад

ELSA-2019-1972: ruby:2.5 security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2020-00760

больше 6 лет назад

Уязвимость функции sure_loadable_spec системы управления пакетами RubyGems, связанная с ошибками обработки многострочных имен, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-8322

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-8322

почти 7 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-8322

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-8322

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The g ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mh37-8c3g-3fgc

больше 6 лет назад

RubyGems Escape sequence injection vulnerability in gem owner

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2020-00753

больше 6 лет назад

Уязвимость команды gem owner системы управления пакетами RubyGems, связанная с выводом содержимого ответа API в стандартный поток вывода, позволяющая нарушителю нарушить целостность данных

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-8325

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-8325

почти 7 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2019-1235

ELSA-2019-1235: ruby security update (IMPORTANT)

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1771-1

Security update for ruby-bundled-gems-rpmhelper, ruby2.5

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1804-1

Security update for ruby-bundled-gems-rpmhelper, ruby2.5

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:1570-1

Security update for ruby2.1

больше 5 лет назад
ubuntu логотип
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 7.2
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
rocky логотип
RLSA-2019:1972

Important: ruby:2.5 security update

1%
Низкий
больше 6 лет назад
github логотип
GHSA-76wm-422q-92mq

Code injection in RubyGems

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
oracle-oval логотип
ELSA-2019-1972

ELSA-2019-1972: ruby:2.5 security update (IMPORTANT)

больше 6 лет назад
fstec логотип
BDU:2020-00760

Уязвимость функции sure_loadable_spec системы управления пакетами RubyGems, связанная с ошибками обработки многострочных имен, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 5.3
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The g ...

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
github логотип
GHSA-mh37-8c3g-3fgc

RubyGems Escape sequence injection vulnerability in gem owner

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
fstec логотип
BDU:2020-00753

Уязвимость команды gem owner системы управления пакетами RubyGems, связанная с выводом содержимого ответа API в стандартный поток вывода, позволяющая нарушителю нарушить целостность данных

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-8325

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

CVSS3: 7.5
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-8325

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

CVSS3: 5.3
0%
Низкий
почти 7 лет назад

Уязвимостей на страницу