ZeroHour

CVE-2017-10784

CVSS 3.0
8.8 high
EPSS
16%p97
Published
()
Modified
Description

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.

Vendors
ruby-lang
Products
ruby
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.