Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:19115
HistoryMay 16, 2019 - 2:49 a.m.

Command Injection

2019-05-1602:49:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.028 Low

EPSS

Percentile

90.7%

Ruby is vulnerable to command injection attacks. This is because lazy_initialize function in lib/resolv.rb do not properly process certain filenames. A remote attacker could possibly exploit this flaw to inject and execute arbitrary commands.