Lucene search

K
osvGoogleOSV:CVE-2019-8324
HistoryJun 17, 2019 - 7:15 p.m.

CVE-2019-8324

2019-06-1719:15:11
Google
osv.dev
9

8.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.