VDB
Sign up
MEDIUM

GHSA-6mq2-37j5-w6r6

WEBrick Improper Input Validation vulnerability

Quick fix

GHSA-6mq2-37j5-w6r6 — webrick: upgrade to the fixed version with the command below.

bundle update webrick

Details

WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/webrick
Introduced in: 0Fixed in: 1.4.0
Fixbundle update webrick

References