CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:H/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS
Percentile
69.7%
Mechanize is an open-source ruby library that makes automated web
interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7
there is a command injection vulnerability. Affected versions of mechanize
allow for OS commands to be injected using several classes’ methods which
implicitly use Ruby’s Kernel.open method. Exploitation is possible only if
untrusted input is used as a local filename and passed to any of these
calls: Mechanize::CookieJar#load, Mechanize::CookieJar#save_as,
Mechanize#download, Mechanize::Download#save, Mechanize::File#save, and
Mechanize::FileResponse#read_body. This is fixed in version 2.7.7.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | ruby-mechanize | < any | UNKNOWN |
ubuntu | 20.04 | noarch | ruby-mechanize | < any | UNKNOWN |
ubuntu | 22.04 | noarch | ruby-mechanize | < any | UNKNOWN |
ubuntu | 16.04 | noarch | ruby-mechanize | < any | UNKNOWN |
github.com/sparklemotion/mechanize/commit/2ac906b26f4a565a0af92df5fb9c8a36c2b75375 (v2.7.7)
github.com/sparklemotion/mechanize/commit/63f8779e49664d5e95fae8d42d04c8e373162b3c (v2.7.7)
github.com/sparklemotion/mechanize/commit/66a6a1bfa653a5f13274a396a5e5441238656aa0
github.com/sparklemotion/mechanize/commit/aae0b13514a1a0caf93b1cf233733c50e679069a (v2.7.7)
github.com/sparklemotion/mechanize/commit/b48b12f5db33c5a94a14dfcab8adf3e73cfa0388 (v2.7.7)
github.com/sparklemotion/mechanize/commit/f43a3952ab39341136656b0a8b2c8597ba1b4adc (v2.7.7)
github.com/sparklemotion/mechanize/releases/tag/v2.7.7
github.com/sparklemotion/mechanize/security/advisories/GHSA-qrqm-fpv6-6r8g
launchpad.net/bugs/cve/CVE-2021-21289
nvd.nist.gov/vuln/detail/CVE-2021-21289
rubygems.org/gems/mechanize/
security-tracker.debian.org/tracker/CVE-2021-21289
www.cve.org/CVERecord?id=CVE-2021-21289
CVSS2
Attack Vector
NETWORK
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:H/Au:N/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS
Percentile
69.7%