445
VMScore

CVE-2019-8322

Published: 17/06/2019 Updated: 19/08/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

An issue exists in RubyGems 2.6 and later up to and including 3.0.2. The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rubygems rubygems

debian debian linux 9.0

opensuse leap 15.0

opensuse leap 15.1

Vendor Advisories

Debian Bug report logs - #925987 CVE-2019-8320 CVE-2019-8321 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 Package: jruby; Maintainer for jruby is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Source for jruby is src:jruby (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debia ...
Several vulnerabilities have been discovered in the Rubygems included in the interpreter for the Ruby language, which may result in denial of service or the execution of arbitrary code For the stable distribution (stretch), these problems have been fixed in version 233-1+deb9u6 We recommend that you upgrade your ruby23 packages For the detail ...
Synopsis Important: ruby security update Type/Severity Security Advisory: Important Topic An update for ruby is now available for Red Hat Enterprise Linux 74 Advanced Update Support, Red Hat Enterprise Linux 74 Telco Extended Update Support, and Red Hat Enterprise Linux 74 Update Services for SAP Solutio ...
Synopsis Important: rh-ruby24-ruby security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for rh-ruby24-ruby is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: CloudForms 475 security, bug fix and enhancement update Type/Severity Security Advisory: Important Topic An update is now available for CloudForms Management Engine 510Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scor ...
Synopsis Important: rh-ruby25-ruby security, bug fix, and enhancement update Type/Severity Security Advisory: Important Topic An update for rh-ruby25-ruby is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: ruby security update Type/Severity Security Advisory: Important Topic An update for ruby is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which ...
An issue was discovered in RubyGems 26 and later through 302 The gem owner command outputs the contents of the API response directly to stdout Therefore, if the response is crafted, escape sequence injection may occur (CVE-2019-8322) An issue was discovered in RubyGems 26 and later through 302 Gem::GemcutterUtilities#with_response may out ...
An issue was discovered in RubyGems The gem owner command outputs the contents of the API response directly to stdout Therefore, if the response is crafted, escape sequence injection may occur(CVE-2019-8322) An issue was discovered in RubyGems Gem::GemcutterUtilities#with_response may output the API response to stdout as it is Therefore, if th ...