VDB
Sign up
MEDIUM

GHSA-hh2x-7mf9-78fr

Sup Code Injection vulnerability

Quick fix

GHSA-hh2x-7mf9-78fr — sup: upgrade to the fixed version with the command below.

bundle update sup

Details

`lib/sup/message_chunks.rb` in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the content_type of an email attachment.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/sup
Introduced in: 0Fixed in: 0.13.2.1
Fixbundle update sup
RubyGems/sup
Introduced in: 0.14.0Fixed in: 0.14.1.1
Fixbundle update sup

References