Lucene search

K
osvGoogleOSV:GHSA-73QW-WW62-M54X
HistoryOct 24, 2017 - 6:33 p.m.

colorscore Command Injection vulnerability

2017-10-2418:33:36
Google
osv.dev
4

0.006 Low

EPSS

Percentile

79.4%

The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) image_path, (2) colors, or (3) depth variable.

0.006 Low

EPSS

Percentile

79.4%

Related for OSV:GHSA-73QW-WW62-M54X