Lucene search

K
osvGoogleOSV:GHSA-FR32-GR5C-XQ5C
HistoryJun 20, 2019 - 4:06 p.m.

RubyGems Escape sequence injection vulnerability in verbose

2019-06-2016:06:04
Google
osv.dev
14

0.002 Low

EPSS

Percentile

58.4%

An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::UserInteraction#verbose calls say without escaping, escape sequence injection is possible.