Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:18921
HistoryMay 16, 2019 - 2:16 a.m.

Privilege Escalation

2019-05-1602:16:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15

0.02 Low

EPSS

Percentile

89.0%

RubyGems is vulnerable to privilege escalation attacks. A remote, unauthenticated attacker could elevate their privileges by interacting with the terminal via the use of escape sequences with a specifically crafted gem. Improper sanitization of gems’ specification text enables the attacker to exploit this vulnerability.