VDB
Sign up
MEDIUM

GHSA-5f2p-6vjv-2q2m

Sup Code Injection vulnerability

Quick fix

GHSA-5f2p-6vjv-2q2m — sup: upgrade to the fixed version with the command below.

bundle update sup

Details

Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sup
Introduced in: 0Fixed in: 0.13.2.1
Fixbundle update sup
RubyGems/sup
Introduced in: 0.14.0Fixed in: 0.14.1.1
Fixbundle update sup

References