VDB
Sign up
HIGH8.8

GHSA-369m-2gv6-mw28

WEBrick RCE Vulnerability

Quick fix

GHSA-369m-2gv6-mw28 — webrick: upgrade to the fixed version with the command below.

bundle update webrick

Details

The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/webrick
Introduced in: 0Fixed in: 1.4.0
Fixbundle update webrick

References