CRITICAL9.8
GHSA-7gcp-2gmq-w3xh
RubyGems Code Injection vulnerability
Quick fix
GHSA-7gcp-2gmq-w3xh — rubygems-update: upgrade to the fixed version with the command below.
bundle update rubygems-updateDetails
RubyGems prior to 2.6.13 is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-0899[ADVISORY]
- https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1[WEB]
- https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491[WEB]
- https://hackerone.com/reports/226335[WEB]
- https://access.redhat.com/errata/RHSA-2017:3485[WEB]
- https://access.redhat.com/errata/RHSA-2018:0378[WEB]
- https://access.redhat.com/errata/RHSA-2018:0583[WEB]
- https://access.redhat.com/errata/RHSA-2018:0585[WEB]
- https://github.com/rubygems/rubygems[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.html[WEB]
- https://security.gentoo.org/glsa/201710-01[WEB]
- https://web.archive.org/web/20170907215801/http://www.securitytracker.com/id/1039249[WEB]
- https://web.archive.org/web/20170915000000*/http://www.securityfocus.com/bid/100576#:~:text=1%20snapshot-,11%3A49%3A33,-Note[WEB]
- https://www.debian.org/security/2017/dsa-3966[WEB]
- http://blog.rubygems.org/2017/08/27/2.6.13-released.html[WEB]