ZeroHour

CVE-2019-8323

CVSS 3.1
7.5 high
EPSS
3%p88
Published
()
Modified
Description

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.

Vendors
rubygemsdebianopensuse
Products
rubygems, debian linux, leap
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.