CVE-2019-8322

HIGH7.5EPSS 0.33%

RubyGems Escape sequence injection vulnerability in gem owner

發布日:2019/6/20修改日:2025/11/19
也稱為:GHSA-mh37-8c3g-3fgcALPINE-CVE-2019-8322DEBIAN-CVE-2019-8322

描述

An issue was discovered in RubyGems 2.6 and later through 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

受影響套件(4)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

參考連結(8)