Lucene search

K
cveRedhatCVE-2013-2090
HistoryMay 27, 2014 - 3:00 p.m.

CVE-2013-2090

2014-05-2715:00:00
CWE-78
redhat
web.nvd.nist.gov
35
creme fraiche
ruby
cve-2013-2090
remote command execution
email attachment

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.014

Percentile

86.5%

The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the file name of an email attachment. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
uplawskicreme_fraicheRange0.6ruby
OR
uplawskicreme_fraicheMatch0.4.5ruby
OR
uplawskicreme_fraicheMatch0.4.5.1ruby
OR
uplawskicreme_fraicheMatch0.4.5.2ruby
OR
uplawskicreme_fraicheMatch0.4.5.4ruby
OR
uplawskicreme_fraicheMatch0.4.5.5ruby
OR
uplawskicreme_fraicheMatch0.4.5.6ruby
OR
uplawskicreme_fraicheMatch0.5ruby
OR
uplawskicreme_fraicheMatch0.5.1ruby
OR
uplawskicreme_fraicheMatch0.5.2ruby
OR
uplawskicreme_fraicheMatch0.5.3ruby
VendorProductVersionCPE
uplawskicreme_fraiche*cpe:2.3:a:uplawski:creme_fraiche:*:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.4.5cpe:2.3:a:uplawski:creme_fraiche:0.4.5:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.4.5.1cpe:2.3:a:uplawski:creme_fraiche:0.4.5.1:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.4.5.2cpe:2.3:a:uplawski:creme_fraiche:0.4.5.2:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.4.5.4cpe:2.3:a:uplawski:creme_fraiche:0.4.5.4:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.4.5.5cpe:2.3:a:uplawski:creme_fraiche:0.4.5.5:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.4.5.6cpe:2.3:a:uplawski:creme_fraiche:0.4.5.6:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.5cpe:2.3:a:uplawski:creme_fraiche:0.5:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.5.1cpe:2.3:a:uplawski:creme_fraiche:0.5.1:*:*:*:*:ruby:*:*
uplawskicreme_fraiche0.5.2cpe:2.3:a:uplawski:creme_fraiche:0.5.2:*:*:*:*:ruby:*:*
Rows per page:
1-10 of 111

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.014

Percentile

86.5%