Логотип exploitDog
bind:"CVE-2019-8324" OR bind:"CVE-2019-8322" OR bind:"CVE-2019-8323" OR bind:"CVE-2019-8325"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2019-8324" OR bind:"CVE-2019-8322" OR bind:"CVE-2019-8323" OR bind:"CVE-2019-8325"

Количество 30

Количество 30

oracle-oval логотип

ELSA-2019-1235

около 6 лет назад

ELSA-2019-1235: ruby security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:1771-1

почти 6 лет назад

Security update for ruby-bundled-gems-rpmhelper, ruby2.5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1804-1

почти 6 лет назад

Security update for ruby-bundled-gems-rpmhelper, ruby2.5

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1570-1

около 5 лет назад

Security update for ruby2.1

EPSS: Низкий
ubuntu логотип

CVE-2019-8324

около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2019-8324

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 7.2
EPSS: Низкий
nvd логотип

CVE-2019-8324

около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-8324

около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...

CVSS3: 8.8
EPSS: Низкий
rocky логотип

RLSA-2019:1972

почти 6 лет назад

Important: ruby:2.5 security update

EPSS: Низкий
github логотип

GHSA-76wm-422q-92mq

почти 6 лет назад

Code injection in RubyGems

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2019-1972

почти 6 лет назад

ELSA-2019-1972: ruby:2.5 security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2020-00760

около 6 лет назад

Уязвимость функции sure_loadable_spec системы управления пакетами RubyGems, связанная с ошибками обработки многострочных имен, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-8322

около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-8322

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-8322

около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-8322

около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The g ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mh37-8c3g-3fgc

почти 6 лет назад

RubyGems Escape sequence injection vulnerability in gem owner

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2020-00753

около 6 лет назад

Уязвимость команды gem owner системы управления пакетами RubyGems, связанная с выводом содержимого ответа API в стандартный поток вывода, позволяющая нарушителю нарушить целостность данных

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2019-8325

около 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2019-8325

больше 6 лет назад

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2019-1235

ELSA-2019-1235: ruby security update (IMPORTANT)

около 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1771-1

Security update for ruby-bundled-gems-rpmhelper, ruby2.5

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1804-1

Security update for ruby-bundled-gems-rpmhelper, ruby2.5

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:1570-1

Security update for ruby2.1

около 5 лет назад
ubuntu логотип
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
1%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 7.2
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.

CVSS3: 8.8
1%
Низкий
около 6 лет назад
debian логотип
CVE-2019-8324

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...

CVSS3: 8.8
1%
Низкий
около 6 лет назад
rocky логотип
RLSA-2019:1972

Important: ruby:2.5 security update

1%
Низкий
почти 6 лет назад
github логотип
GHSA-76wm-422q-92mq

Code injection in RubyGems

CVSS3: 8.8
1%
Низкий
почти 6 лет назад
oracle-oval логотип
ELSA-2019-1972

ELSA-2019-1972: ruby:2.5 security update (IMPORTANT)

почти 6 лет назад
fstec логотип
BDU:2020-00760

Уязвимость функции sure_loadable_spec системы управления пакетами RubyGems, связанная с ошибками обработки многострочных имен, позволяющая нарушителю выполнить произвольный код

CVSS3: 8.8
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 5.3
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

CVSS3: 7.5
0%
Низкий
около 6 лет назад
debian логотип
CVE-2019-8322

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The g ...

CVSS3: 7.5
0%
Низкий
около 6 лет назад
github логотип
GHSA-mh37-8c3g-3fgc

RubyGems Escape sequence injection vulnerability in gem owner

CVSS3: 7.5
0%
Низкий
почти 6 лет назад
fstec логотип
BDU:2020-00753

Уязвимость команды gem owner системы управления пакетами RubyGems, связанная с выводом содержимого ответа API в стандартный поток вывода, позволяющая нарушителю нарушить целостность данных

CVSS3: 7.5
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-8325

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

CVSS3: 7.5
0%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-8325

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)

CVSS3: 5.3
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу